Trust center

Know what connects, what is collected, and where the boundaries are.

TenantShield uses different data flows for the public site, free tools, and paid services. This page explains those differences before you use them.

Four distinct data flows

Use only the access level the task requires.

PUBLIC SITE

Marketing pages

Standard web requests plus optional analytics after your choice. Contact details are processed only when you submit an inquiry.

NO TENANT ACCESS

External Exposure Scan

The domain you enter is sent to the scan service to evaluate public DNS and email-security records.

DELEGATED READ

Browser Checker

Microsoft Graph queries and result processing run in your browser after Microsoft sign-in and consent.

AGREED SCOPE

Professional services

Evidence, access, retention, contacts, and deliverables are defined for the engagement before work begins.

Browser Checker

Read-only Microsoft Graph permissions requested.

The current Browser Checker requests delegated permissions. Microsoft presents the consent request, and a Microsoft Entra administrator controls whether the delegated permissions are granted.

PermissionWhy the checker requests it
Directory.Read.AllRead directory objects relevant to tenant posture.
Policy.Read.AllRead identity and access policy configuration.
Reports.Read.AllRead supported Microsoft 365 usage and security reports.
UserAuthenticationMethod.Read.AllEvaluate authentication-method registration coverage.
Organization.Read.AllRead organization and licensing context.
SecurityAlert.Read.AllRead supported Microsoft Defender XDR alert signals.
IdentityRiskyUser.Read.AllRead supported Microsoft Entra ID Protection risky-user signals.
AuditLog.Read.AllRead directory audit and sign-in signals used by checks.
DeviceManagementManagedDevices.Read.AllRead managed-device posture where Microsoft Intune is in use.
DeviceManagementConfiguration.Read.AllRead applicable Microsoft Intune configuration.
Application.Read.AllReview enterprise applications, service principals, and consent posture.
Read-only does not mean low sensitivity. These permissions can expose security-relevant metadata. Use an authorized account, review Microsoft’s consent screen, and revoke access when finished if that matches your policy.
In-browser processing

How the checker session works.

  • Authentication is handled by the Microsoft Authentication Library for JavaScript (MSAL.js).
  • Authentication state is stored in browser session storage.
  • Microsoft Graph API calls are made from the browser.
  • Results are rendered in the browser and are not sent to TenantShield.
  • CSV or report exports happen only when you request them.
Analytics boundary

Finding data stays out of analytics.

When optional analytics are enabled, TenantShield reports only generic product-use milestones—such as whether a check completed—not tenant ID, entered domain, score, finding name, raw evidence, user identity, or access token.

Microsoft Clarity is limited to marketing pages and is excluded from both public tools. The tool pages can use Google Analytics only after the visitor allows optional analytics.

After use

End the session and revoke access when required.

  1. Use the “Sign out of Microsoft” control in the Browser Checker. It clears the rendered tenant results and asks MSAL.js to clear its token cache and redirect through Microsoft sign-out.
  2. Let the Microsoft sign-out navigation finish, then close the browser tab. If it cannot finish, close the tab and clear this site’s session storage.
  3. If your organization requires it, review or revoke the application’s delegated permissions in the Microsoft Entra admin center.
  4. Use Microsoft Entra audit logs to confirm consent and sign-in activity.

Microsoft Entra admin center experiences and role requirements can change. Follow your organization’s administration process and current Microsoft documentation.

Report an issue

Security questions deserve a direct path.

To report a suspected vulnerability or ask about data handling, email jason@tenantshield.io. Do not include access tokens, passwords, private keys, or sensitive tenant exports in the first message.

Automated security-contact details are also published at /.well-known/security.txt.

Need to review access before an engagement?

Ask for the proposed evidence and access plan before deciding whether to proceed.