Legal
Privacy Policy
Last updated: June 1, 2026
AzureProof ("we", "us") is a SOC2 evidence-collection tool for Microsoft Azure tenants. This policy explains what we collect, why, and your rights. Template — to be reviewed by counsel before launch.
1. Information we collect
- Account data: name, work email, company name, password hash.
- Tenant credentials: Azure tenant ID, client ID, encrypted client secret.
- Evidence metadata: control IDs, pass/fail status, evidence pointers, run timestamps.
- Usage data: pages visited, actions taken, IP, user agent.
2. How we use it
- To deliver the service (running evidence checks against your tenant).
- For billing, support, and security investigations.
- For aggregated product analytics (no PII shared).
3. What we don't do
- We never sell your data.
- We never modify your Azure tenant — read-only Graph API access.
- We never train AI models on your evidence.
4. Sub-processors
See our Trust page for the full list of sub-processors.
5. Your rights (GDPR / CCPA)
You can request access, correction, export, or deletion at privacy@azureproof.com.
6. Contact
privacy@azureproof.com