You are buying a security review. Here is ours.
A supplier that assesses your environment should be able to answer the questions it is about to ask you. This page is the answer, including the parts that are still unfinished.
01 — How we reach your environment
Collection reads configuration and reporting data from Microsoft 365, Active Directory, and Azure. There are two ways to authorise it, and most engagements use the first.
Interactive sign-in. An account you control, holding read-only administrative roles, signs in for the duration of the collection. The session expires. Nothing standing is created, and there is nothing to revoke afterwards because nothing is left behind.
Registered application. Where you want unattended or repeated collection, we register an application in your directory that authenticates with a certificate rather than a shared secret, holding a read-only directory role and nothing above it. Consent is never granted automatically. You open the consent screen yourself, read the permission list, and decide. Revoking it is deleting the application.
Either way, you can see the full permission list before you approve anything, and we will walk you through it line by line if you want that.
02 — What the access cannot do
The access carries no permission to read the contents of mailboxes, files, document libraries, chat messages, or notebooks. Those permissions are not requested, so they do not appear on your consent screen and could not be exercised if something tried.
Nothing we run writes to your environment. We do not remediate, toggle a setting, create an account, or change a policy. Every finding lands in a report that tells you what to change, in your own change process, at your own pace. If answering a question would require a write permission, the question does not get answered.
What the collection does see is configuration: policies, role assignments, licensing, authentication methods, audit settings, and the account inventory those settings apply to. Account names and email addresses are personal data, handled under the Privacy Policy.
03 — How findings are handled
Collected data and the findings derived from it are encrypted in transit and at rest, and held in the United States. Your data is segregated from every other client’s. Credentials that could reach it are never exposed to a browser, and draft reports are not kept anywhere that would put them outside those controls.
Findings are kept while they are useful to you, for a renewal or an audit, and deleted after that. Ask for deletion sooner and we do it sooner. Retention specific to your engagement is set out in the agreement you sign, not left to a web page.
04 — Who can see them
Access to your findings is limited to the people working your engagement, on the principle of least privilege, and every account that can reach client data is individually authenticated and permission-scoped to what its holder needs. Access is removed when it is no longer needed. Your engagement agreement names who will be working on it.
TenantSquared is a small firm. That is the reason the list of people who can see your data is short, and it is a deliberate part of how the service is delivered.
05 — The CUI rule
We never collect or store Controlled Unclassified Information. Not in the assessment, not in a form on this site, not in an email thread. This constrains the product: it is why the request form asks you not to include contract numbers or CAGE codes, and why a finding that would require CUI to state is a finding we do not make.
It also means we are not a candidate for handling CUI on your behalf, and a Baseline is not an assessment of a CUI enclave. If CUI reaches us by accident, tell us and we destroy it and confirm in writing.
06 — If something goes wrong
If we discover a breach affecting your data, we will tell you without waiting to be asked, and we will say what happened, which of your data was involved, when, and what we changed as a result. We will do it in writing, and we will not wait for the end of an investigation to make the first contact.
07 — What we have not done
We do not hold a SOC 2 report, an ISO 27001 certificate, or a FedRAMP authorisation, and we have not had a third-party penetration test. We are a young company and claiming otherwise would be the exact behaviour this product exists to catch. If one of those is necessary for the work you want done, say so and we will talk about the timeline honestly rather than implying it already exists.
The unattended collection path is newer than the interactive one and is still being proven. Where that matters to an engagement, we use the interactive path.
08 — Reporting a vulnerability
Send anything you find to privacy@patriot7six.com with enough detail to reproduce it. We acknowledge within five business days and keep you posted until it is closed. We will not pursue anyone who reports in good faith, stays within their own test data, and gives us reasonable time before publishing. We do not currently pay a bounty.