With the client's express authorisation, read-only Microsoft 365 or Google Workspace connectors may process tenant identifiers, domains, licence and service information, and aggregate identity and security-posture metrics. These may include user, guest, group, administrator, MFA, two-step verification, passwordless, self-service password reset, Conditional Access, and audit-report availability counts or signals.
The platform is designed not to retain passwords, email or file contents, or raw cloud directory payloads. It records normalised snapshots, consent and connection status, sync history, detected signals, and advisory review outcomes. The authorising administrator can revoke access through the relevant cloud provider.