Legal

Privacy Policy

Last updated 21 August 2026

This policy is provided in good faith to describe how the service handles data. It is not legal advice; please have it reviewed by your own legal adviser before relying on it commercially.

1. Who we are

Cloud Audit Check ("we", "us") provides a read-only security and compliance assessment service for Microsoft 365 and Microsoft Azure environments. This policy explains what data we handle when you use the service at cloudauditcheck.com.

2. What we access — and what we never touch

Cloud Audit Check connects to your Microsoft 365 tenant and Azure subscriptions using an app registration that you create and consent to, with read-only permissions. We use it solely to read security configuration and posture.

We do not read, store, or process the content of your mailboxes, files, chats, or documents. For example, the external-forwarding check reads inbox rule definitions only (via MailboxSettings.Read) — never the body of any message. We only ever read configuration and metadata needed to evaluate a security control.

3. Data we collect

Account data: your name, email address, organisation name, and hashed password (we never store passwords in plain text).

Tenant configuration and assessment results: the pass/fail outcome of each security check, the specific configuration evidence behind a finding (for example, which user accounts lack MFA, which storage account allows public access), scores, and history over time.

Operational data: log data needed to run and secure the service.

4. How we use your data

To run assessments, generate findings and reports, track your posture over time, send the notifications you enable (assessment complete, score-drop alerts, weekly digest), and to operate, secure, and support the service.

We do not sell your data. We do not use your tenant data to train machine-learning models. We do not share it with third parties except the sub-processors needed to run the service (below).

5. Where your data lives (Australian residency)

Cloud Audit Check is hosted in Sydney, Australia. Your account data and assessment results are stored in Australia and do not leave the country in the ordinary course of operating the service.

6. Security

Access to your Microsoft 365 / Azure tenant is read-only. The credential used to connect (your Azure app client secret) is encrypted at rest using AES-256-GCM and is never returned to your browser. Data is transmitted over TLS. Access to production systems is restricted.

7. Data retention

We retain assessment results while your account is active so you can track progress over time. When you disconnect a tenant, its stored assessment data is removed. When you close your account, we delete your data within a reasonable period, except where we must retain limited records to meet legal obligations.

8. Sub-processors

We use a small number of infrastructure providers to run the service (application hosting in Australia, and an email delivery provider for the notifications you enable). These providers process data only to provide their service to us.

9. Your rights

You can access, correct, export, or delete your account and assessment data. To make a request, contact us using the details below. We handle personal information consistently with the Australian Privacy Principles.

10. Changes and contact

We may update this policy; material changes will be notified in-product or by email. For any privacy question or request, contact privacy@cloudauditcheck.com.