Understand what TPZ can access, how customer information is handled, and the controls that govern how the platform operates.

SECURITY & DATA

WHAT TPZ ACCESSES

TPZ’s current Microsoft Entra integration is read-only. We access the identity and security information needed to identify risk and provide the product experience.

WHEN MICROSOFT ENTRA IS CONNECTED, TPZ CURRENTLY READS:

Users and accounts
Users and accounts

USERS &
ACCOUNTS

Names, email/UPN, department, job title, account status, and basic account metadata.

Sign-in activity
Sign-in activity

ROLES &
PRIVILEGES

Assigned Entra directory roles and the identities that hold them.

Identity risk
Identity risk

SIGN-IN
ACTIVITY

Sign-in time, application, IP address, approximate location, success or failure, and risk signals.

Access policies
Access policies

IDENTITY
RISK

Microsoft Identity Protection risky-user and risk-detection signals.

Directory activity
Directory activity

ACCESS
POLICIES

Conditional Access policy information.

Roles and privileges
Roles and privileges

DIRECTORY
ACTIVITY

Relevant Microsoft Entra audit events used for activity visibility.

Security posture
Security posture

SECURITY
POSTURE

Microsoft Secure Score information used in posture reporting.

Authentication posture
Authentication posture

AUTHENTICATION
POSTURE

MFA registration status and authentication method types.

Applications and service accounts
Applications and service accounts

APPLICATIONS &
SERVICE ACCOUNTS

Application registrations, enterprise apps, service principals, permissions, and credential-expiration metadata.

WHY TPZ ACCESSES IT
To build identity and access visibility, identify security concerns, calculate risk and posture indicators, and prioritize what requires attention.

SECURITY & DATA

WHAT TPZ DOES NOT ACCESS

TPZ is designed for identity and access visibility. We do not access the following types of data.

Email content not accessed by TPZ
Email content not accessed by TPZ

EMAIL CONTENT

We do not read or store email messages, attachments, or metadata.

Teams and chat content not accessed by TPZ
Teams and chat content not accessed by TPZ

TEAMS &
CHAT CONTENT

We do not access Teams messages, channel content, or chat conversations.

Files and document content not accessed by TPZ
Files and document content not accessed by TPZ

PASSWORDS &
SECRETS

We do not access or store passwords, secrets, API keys, or authentication tokens.

Passwords and secrets not accessed by TPZ
Passwords and secrets not accessed by TPZ

FILES &
DOCUMENT CONTENT

We do not access the content of files, documents, or assets in any system.

Payment information not accessed by TPZ
Payment information not accessed by TPZ

PAYMENT
INFORMATION

We do not access any payment card data or financial account information.

Source code not accessed by TPZ
Source code not accessed by TPZ

SOURCE CODE & DEVELOPMENT CONTENT

For agreed integrations such as GitHub, TPZ accesses only the identity, access, permission, and configuration metadata needed for the supported workflow.

Personal data outside identity and access management not accessed by TPZ
Personal data outside identity and access management not accessed by TPZ

PERSONAL DATA
OUTSIDE IAM

We do not access personal data that is not required for identity and access analysis.

Browsing activity not accessed by TPZ
Browsing activity not accessed by TPZ

BROWSING
ACTIVITY

We do not monitor web browsing activity or capture full session recordings.

Data from unconnected tools not accessed by TPZ
Data from unconnected tools not accessed by TPZ

DATA FROM
UNCONNECTED TOOLS

We do not access data from security tools or systems that are not connected to TPZ.

TPZ limits data access to the information required for the product to work.

SECURITY & DATA

HOW DATA IS USED & STORED

TPZ uses connected identity and security data to identify risk, calculate posture, generate findings, and support the views you see in the product.

Analyze and prioritize security risk

ANALYZE & PRIORITIZE

TPZ analyzes connected data to identify security concerns, calculate risk and posture indicators, and generate findings and recommendations.

Encrypted customer data storage

ENCRYPTED STORAGE

Customer data used by TPZ is stored in encrypted AWS infrastructure. TPZ stores normalized identity, role, application, policy, score, and sign-in information needed to power the product.

Organization-scoped customer data

ORGANIZATION-SCOPED

Customer data is scoped to the organization it belongs to and separated from other TPZ customer environments.

Securely separated connection credentials

SECRETS STORED SEPARATELY

Connection credentials and other secrets are handled separately through AWS Secrets Manager rather than being stored as plaintext in the TPZ application database.

Optional AI assistant data processing

OPTIONAL AI ASSISTANT

When the AI Assistant is used, TPZ sends the conversation and a limited dashboard snapshot to the AI provider. The full identity directory is not automatically included. Chat history is kept in the browser session rather than stored in TPZ’s database.

SECURITY & DATA

Read-Only Today,
Governed Actions Next.

TPZ starts with visibility, not control. Our current Microsoft Entra integration is read-only, so we can identify risk, prioritize what matters, and recommend next steps without changing your environment.

Future action capabilities are designed around policy checks, approvals, and verification before execution.

Future action capabilities are being designed around policy checks, approvals, and verification before execution.

See it

Read-Only Today

Simulate First

We show you the impact, requirements, and expected results before anything happens.

We only read the data you connect. Nothing is changed in Microsoft Entra or Azure.

You Stay in Control

Actions that require approval do not proceed until that approval is given.

Governed Execution

Only approved actions are performed through controlled, allowlisted operations.

Verify & Record

We confirm the result and capture evidence for complete accountability.

OUR APPROACH

Simulate it

Approve it

Execute it

Verify it

SECURITY & DATA

Third-Party Providers

& Subprocessors

TPZ uses third-party providers for cloud infrastructure, connected Microsoft services, authentication, and optional AI functionality.

Amazon Web Services
Cloud infrastructure

Microsoft
Connected identity and cloud services

Google
Optional authentication

Anthropic
Powers TPZ’s optional AI Assistant

*Google and Anthropic are used only when the related optional feature is used.

SECURITY & DATA

Security & Compliance

TPZ uses technical and operational controls to protect customer data and the systems that process it.

ENCRYPTED INFRASTRUCTURE

Customer data stored by TPZ is encrypted at rest within AWS infrastructure.

ORGANIZATION-SCOPED ACCESS

Customer data is associated with the organization it belongs to, with authentication and authorization controls used to separate access across TPZ customer environments.

CREDENTIAL PROTECTION

Connection credentials, API keys, and other secrets are managed separately through AWS Secrets Manager rather than stored as plaintext in the application database. Microsoft access tokens are held in memory rather than persisted in the TPZ database.

SECURITY MONITORING

TPZ maintains application, infrastructure, and edge logs for security monitoring and troubleshooting.

COMPLIANCE & ASSURANCE

TPZ is currently working toward SOC 2 assurance. TPZ does not represent itself as SOC 2 compliant or as having completed a SOC 2 examination.

Security documentation and additional information are available upon request.