Understand what TPZ can access, how customer information is handled, and the controls that govern how the platform operates.
SECURITY & DATA
WHAT TPZ ACCESSES
TPZ’s current Microsoft Entra integration is read-only. We access the identity and security information needed to identify risk and provide the product experience.
WHEN MICROSOFT ENTRA IS CONNECTED, TPZ CURRENTLY READS:
USERS &
ACCOUNTS
Names, email/UPN, department, job title, account status, and basic account metadata.
ROLES &
PRIVILEGES
Assigned Entra directory roles and the identities that hold them.
SIGN-IN
ACTIVITY
Sign-in time, application, IP address, approximate location, success or failure, and risk signals.
IDENTITY
RISK
Microsoft Identity Protection risky-user and risk-detection signals.
ACCESS
POLICIES
Conditional Access policy information.
DIRECTORY
ACTIVITY
Relevant Microsoft Entra audit events used for activity visibility.
SECURITY
POSTURE
Microsoft Secure Score information used in posture reporting.
AUTHENTICATION
POSTURE
MFA registration status and authentication method types.
APPLICATIONS &
SERVICE ACCOUNTS
Application registrations, enterprise apps, service principals, permissions, and credential-expiration metadata.
WHY TPZ ACCESSES IT
To build identity and access visibility, identify security concerns, calculate risk and posture indicators, and prioritize what requires attention.
SECURITY & DATA
WHAT TPZ DOES NOT ACCESS
TPZ is designed for identity and access visibility. We do not access the following types of data.
EMAIL CONTENT
We do not read or store email messages, attachments, or metadata.
TEAMS &
CHAT CONTENT
We do not access Teams messages, channel content, or chat conversations.
PASSWORDS &
SECRETS
We do not access or store passwords, secrets, API keys, or authentication tokens.
FILES &
DOCUMENT CONTENT
We do not access the content of files, documents, or assets in any system.
PAYMENT
INFORMATION
We do not access any payment card data or financial account information.
SOURCE CODE & DEVELOPMENT CONTENT
For agreed integrations such as GitHub, TPZ accesses only the identity, access, permission, and configuration metadata needed for the supported workflow.
PERSONAL DATA
OUTSIDE IAM
We do not access personal data that is not required for identity and access analysis.
BROWSING
ACTIVITY
We do not monitor web browsing activity or capture full session recordings.
DATA FROM
UNCONNECTED TOOLS
We do not access data from security tools or systems that are not connected to TPZ.
TPZ limits data access to the information required for the product to work.
SECURITY & DATA
HOW DATA IS USED & STORED
TPZ uses connected identity and security data to identify risk, calculate posture, generate findings, and support the views you see in the product.
ANALYZE & PRIORITIZE
TPZ analyzes connected data to identify security concerns, calculate risk and posture indicators, and generate findings and recommendations.
ENCRYPTED STORAGE
Customer data used by TPZ is stored in encrypted AWS infrastructure. TPZ stores normalized identity, role, application, policy, score, and sign-in information needed to power the product.
ORGANIZATION-SCOPED
Customer data is scoped to the organization it belongs to and separated from other TPZ customer environments.
SECRETS STORED SEPARATELY
Connection credentials and other secrets are handled separately through AWS Secrets Manager rather than being stored as plaintext in the TPZ application database.
OPTIONAL AI ASSISTANT
When the AI Assistant is used, TPZ sends the conversation and a limited dashboard snapshot to the AI provider. The full identity directory is not automatically included. Chat history is kept in the browser session rather than stored in TPZ’s database.
SECURITY & DATA
Read-Only Today,
Governed Actions Next.
TPZ starts with visibility, not control. Our current Microsoft Entra integration is read-only, so we can identify risk, prioritize what matters, and recommend next steps without changing your environment.
Future action capabilities are being designed around policy checks, approvals, and verification before execution.
See it
›
Read-Only Today
Simulate First
We show you the impact, requirements, and expected results before anything happens.
We only read the data you connect. Nothing is changed in Microsoft Entra or Azure.
You Stay in Control
Actions that require approval do not proceed until that approval is given.
Governed Execution
Only approved actions are performed through controlled, allowlisted operations.
Verify & Record
We confirm the result and capture evidence for complete accountability.
OUR APPROACH
Simulate it
›
Approve it
›
Execute it
›
Verify it
SECURITY & DATA
Third-Party Providers
& Subprocessors
TPZ uses third-party providers for cloud infrastructure, connected Microsoft services, authentication, and optional AI functionality.
Amazon Web Services
Cloud infrastructure
Microsoft
Connected identity and cloud services
Google
Optional authentication
Anthropic
Powers TPZ’s optional AI Assistant
*Google and Anthropic are used only when the related optional feature is used.
SECURITY & DATA
Security & Compliance
TPZ uses technical and operational controls to protect customer data and the systems that process it.
ENCRYPTED INFRASTRUCTURE
Customer data stored by TPZ is encrypted at rest within AWS infrastructure.
ORGANIZATION-SCOPED ACCESS
Customer data is associated with the organization it belongs to, with authentication and authorization controls used to separate access across TPZ customer environments.
CREDENTIAL PROTECTION
Connection credentials, API keys, and other secrets are managed separately through AWS Secrets Manager rather than stored as plaintext in the application database. Microsoft access tokens are held in memory rather than persisted in the TPZ database.
SECURITY MONITORING
TPZ maintains application, infrastructure, and edge logs for security monitoring and troubleshooting.
COMPLIANCE & ASSURANCE
TPZ is currently working toward SOC 2 assurance. TPZ does not represent itself as SOC 2 compliant or as having completed a SOC 2 examination.
Security documentation and additional information are available upon request.