Legal

Privacy Policy

Last updated: June 1, 2026

AzureProof ("we", "us") is a SOC2 evidence-collection tool for Microsoft Azure tenants. This policy explains what we collect, why, and your rights. Template — to be reviewed by counsel before launch.

1. Information we collect

  • Account data: name, work email, company name, password hash.
  • Tenant credentials: Azure tenant ID, client ID, encrypted client secret.
  • Evidence metadata: control IDs, pass/fail status, evidence pointers, run timestamps.
  • Usage data: pages visited, actions taken, IP, user agent.

2. How we use it

  • To deliver the service (running evidence checks against your tenant).
  • For billing, support, and security investigations.
  • For aggregated product analytics (no PII shared).

3. What we don't do

  • We never sell your data.
  • We never modify your Azure tenant — read-only Graph API access.
  • We never train AI models on your evidence.

4. Sub-processors

See our Trust page for the full list of sub-processors.

5. Your rights (GDPR / CCPA)

You can request access, correction, export, or deletion at privacy@azureproof.com.

6. Contact

privacy@azureproof.com