Skip to content
Security & compliance

Built to pass the security review.

Tenant-aware Microsoft identity, Azure-hosted operations, a signed audit log, least-privilege Graph scopes, and controlled endpoint remediation.

Signed audit log

Tamper-evident activity log with retention, integrity checks, and signed exports.

3f9a…b21csigned
7a11…dd0fsigned
cc83…4e10signed

Least-privilege Graph scopes

Every Microsoft Graph permission is scoped to exactly the capability it enables.

User.Read
GroupMember.Read.All
Mail.Read (support mailbox)

Entra ID-native identity

Microsoft Entra ID for authentication on every plan. Tenant-aware, MFA-friendly.

acme.onmicrosoft.com · signed in

Encryption at rest & in transit

TLS in transit and AES-256 at rest across Azure SQL and Blob Storage.

Data residency (Enterprise)

US or EU Azure regions available on Enterprise for teams with residency requirements.

US region
EU region

SOC 2-ready · GDPR-aware

Working toward SOC 2 Type II with controls in place today. GDPR-aware data handling.

SOC 2
GDPR

Endpoint command guardrails

Pro remediation playbooks are ticket-linked, permissioned, and recorded in the audit trail.

Approval required
Ticket-linked
Audited command
Read our Privacy Policy · need a DPA or security questionnaire? Contact us.

Ship support inside Teams.

7-day free trial. Unlimited agents on every plan. Live in 48 hours.

No credit card requiredCancel during trialMicrosoft AppSource ready