AuthMargin
Privacy

Collect what the assessment needs. Keep the boundaries visible.

This page summarizes how AuthMargin handles product data. Organization-specific contractual, regulatory, and data-processing requirements should be reviewed before connecting production tenant data.

Microsoft 365 access

Audit Mode is read-only by default.

AuthMargin uses customer-approved Microsoft application permissions to collect bounded security and configuration evidence. Protect Mode is a separate opt-in permission set used only for supported, approved remediation actions.

Data handling

Security evidence is treated as customer data.

Evidence

Assessment evidence, findings, control states and scan history are stored for the connected tenant so changes can be investigated and verified over time.

Analytics

Public marketing pages use page, attribution, and conversion analytics. Authenticated workspace page views are excluded; only coarse funnel milestones such as successful connection, completed free assessment, or verified paid activation may be measured there. AuthMargin does not intentionally include Microsoft tenant identifiers, user email addresses, access tokens, scan or job IDs, or scan findings in those analytics events.

Credentials

AuthMargin does not ask customers for their Microsoft passwords. Application credentials and payment integration secrets are kept out of browser-delivered code.

Tenant separation

Tenant scope and product role are enforced by the server-side authenticated session and membership record rather than a browser-supplied tenant identifier.

Support requests

The support form sends the name, reply email, optional company, topic, subject and message to the AuthMargin support inbox. Do not include passwords, access tokens, private keys or unrelated customer evidence.

Deletion and retention

Plan-level audit history controls what customers can retrieve in the product: Business includes 30 days and Pro/MSP include 365 days. Underlying security evidence is retained separately under the production evidence lifecycle for integrity, recovery, and security-investigation purposes, currently up to 400 days, then lifecycle-deleted. Cancellation stops new scheduled collection; already-stored evidence follows that lifecycle unless an earlier deletion is required by contract or applicable law. Customers should not place unrelated sensitive content into AuthMargin notes, support messages or security reports.

Questions about security or privacy?

Review the Trust Center and permission documentation before connecting a production tenant.