Data handling
This page is the contract. If the product ever does something not listed here, that is a bug and a breach of this statement.
What we read
- Directory: users, job titles, manager chain, account status, last sign-in date.
- Membership: security groups, Microsoft 365 groups, Teams, distribution lists, and their owners.
- Ownership: shared mailboxes, SharePoint sites, enterprise apps, admin roles.
- Calendar metadata: organizers and attendees of recurring meetings. Not the meeting content.
- Mail metadata: sender, recipients, date, and thread relationships for the last 90 days. Not the subject line, not the body, not attachments.
What we never read
- Message bodies, attachments, or subject lines.
- Files, documents, chat messages, or meeting transcripts.
- Passwords, MFA state, or anything from personal devices.
How access works
Access is a read-only Microsoft Entra application that a Global Admin consents to. The consent screen lists every scope. You can revoke the application from your tenant at any time and the connection is gone.
How long we keep it
Tenant data is processed in memory to build your report. When the report is delivered it is deleted. We keep the report itself for you to download for 90 days, then delete that too. We keep your email address and purchase record because we have to.
Who sees it
No human on the Bus-Factor Report team reads your tenant data. The report is generated by software and delivered to the email that purchased it. We do not use your data to train anything.
Questions: support@therocketshed.com.