Trust & security

Security you can hand to your board and your auditor.

A security tool has to be trustworthy first. Cloud Audit Check is read-only, least-privilege, encrypted, and hosted in Australia — so connecting your tenant is a low-risk decision.

Australian data residency

Your data is hosted in Australia (Sydney). It does not leave the country — a hard requirement for many Australian businesses and government-adjacent work.

Read-only access

Cloud Audit Check requests read-only Microsoft Graph permissions. It reads your configuration to assess it; it never changes a setting in your tenant.

Least privilege

We ask only for the specific Graph permissions each check needs — nothing broad, nothing write-capable. You see the full list before you consent.

Revoke anytime

Connection is via Microsoft admin consent. Remove the app from Entra, or disconnect in-app, and access ends immediately.

Encrypted at rest

Secrets (like your Azure app credential) are encrypted with AES-256-GCM before they ever touch the database. They are never returned to the browser.

We don’t hoard your data

We store assessment results and findings so you can track progress — not your emails, files, or user content. The audit reads configuration, not data.

Exactly what we ask for

The permissions we request — all read-only

No write access, no mailbox or file content. You approve these in Microsoft’s own admin-consent screen.

Policy.Read.AllRead Conditional Access, authentication methods, and security-default policies.
Organization.Read.AllRead tenant and licence information.
Directory.Read.AllRead users, groups, roles, and domains for identity checks.
RoleManagement.Read.DirectoryRead privileged role assignments (e.g. Global Administrators).
Application.Read.AllRead enterprise apps and service principals for integration checks.
SecurityEvents.Read.AllRead Microsoft Secure Score and control profiles.
AuditLog.Read.AllRead per-user MFA registration and sign-in telemetry.
MailboxSettings.ReadDetect inbox rules that forward mail externally — reads rules only, never message content.
SharePointTenantSettings.Read.AllRead the tenant-wide SharePoint / OneDrive external-sharing setting.
DeviceManagementManagedDevices.Read.AllRead Intune device compliance state.
DeviceManagementConfiguration.Read.AllRead Intune compliance and configuration policies.

Azure is optional and uses role-based access, not Graph permissions: assign the same app registration the read-only Reader and Security Reader roles on your subscription.

What we store

  • Assessment scores, pillars, and findings (so you can track progress)
  • Your tenant’s name, domain, and ID
  • Remediation status you mark
  • Your Azure app credential — encrypted at rest

What we never touch

  • Emails, files, chats, or any user content
  • Passwords or authentication secrets of your users
  • Anything write-capable — we change nothing in your tenant
  • Your data, sold or shared with anyone

Read-only, revocable, and in Australia.

Connect your tenant for a free audit — and disconnect the moment you want to.