How TenantShield handles information across the website, tools, and services.
This notice explains what information may be processed, why it is used, and the choices available to you.
1. Scope
This notice applies to tenantshield.io, its public tools, contact interactions, and information TenantShield handles while discussing or providing services. A signed service agreement may add more specific terms for a customer engagement.
2. Information you provide
TenantShield may receive your name, work email, organization, role, approximate organization size, message, scheduling details, and other information you choose to provide. Do not send credentials, access tokens, private keys, sensitive tenant exports, or regulated data through the public contact form.
3. Website and analytics information
Like most websites, the service receives technical request data such as IP address, browser type, device information, referring page, and requested URL. Optional analytics do not load until you allow them. Marketing pages may then use Google Analytics and Microsoft Clarity to understand aggregate traffic and usability; the public tools may use Google Analytics but not Microsoft Clarity.
Analytics events are designed to exclude tenant IDs, entered domains, names, email addresses, organizations, message contents, public inquiry references, raw findings, finding names, scores, and access tokens. You can change your choice at any time with the control in the footer.
4. External Exposure Scan
When you run the free External Exposure Scan, the domain you enter is sent to the scan service, which uses Google Public DNS to retrieve public DNS and email-security records. Do not submit a domain unless you are authorized to do so. Generic analytics may record that a scan started or completed, but should not include the entered domain, directional indicator, score, or raw result.
5. Browser Checker
The Browser Checker uses Microsoft sign-in and delegated, read-only Microsoft Graph permissions. Graph queries and result processing run in the browser. Authentication state is stored in browser session storage, and exports occur only when requested by the user. Generic analytics may record product-use milestones, but should not include tenant identity, user identity, scores, finding data, raw evidence, OAuth parameters, or access tokens. See Security & data handling for the current permission list.
6. Professional services
For paid work, TenantShield may process customer contacts, engagement communications, approved evidence, working notes, findings, action registers, and deliverables. Access methods, evidence handling, recipients, retention, and deletion expectations should be defined in the engagement scope before access is granted.
7. How information is used
- Provide, secure, troubleshoot, and improve the website, tools, and services.
- Respond to inquiries and prepare a requested scope.
- Prepare, perform, and administer agreed professional services.
- Detect misuse and protect the service.
- Comply with applicable obligations and enforce agreements.
8. Client inquiry records
When you submit an inquiry, TenantShield validates it and stores the record in a first-party database hosted on Cloudflare. The record includes the form fields, consent record, source and campaign fields, and an opaque public reference. TenantShield does not intentionally store your raw IP address or browser user-agent string with the lead record. Formspree may receive a server-side notification copy so the inquiry can be answered; the browser does not submit the form directly to Formspree.
9. Service providers
TenantShield uses service providers to operate the site and requested workflows, including Cloudflare for delivery, security, and inquiry storage; Google Public DNS for public record lookups; Google Analytics for optional measurement; Microsoft Clarity for optional marketing-page usability analytics; Formspree for inquiry notification; and Microsoft for sign-in and Microsoft Graph APIs. Those providers process information under their own terms and privacy notices.
10. Retention
Public inquiry records are scheduled for a retention review 365 days after submission and may be deleted earlier when no longer needed. Records may be retained longer when reasonably needed for an active customer relationship, security and operational records, contractual commitments, dispute handling, or legal obligations. Browser session data can be removed by signing out, closing the session, or clearing browser storage. Customer-specific retention requirements should be documented in the service agreement.
11. Choices and requests
You can keep optional analytics disabled, change your analytics choice, use the public site without submitting a form, avoid the tools, decline Microsoft consent, revoke delegated permissions in the Microsoft Entra admin center, or contact TenantShield about access, correction, or deletion of information you provided. Some records may need to be retained where required by law or contract.
12. Security
TenantShield uses reasonable administrative and technical safeguards appropriate to the service, but no website, transmission, or storage method can be guaranteed completely secure. Report a concern to the address below without including secrets in the initial message.
13. Changes
This notice may change as the service evolves. The effective date at the top will be updated when changes are posted.
14. Contact
Questions or requests: jason@tenantshield.io.