Privacy Policy
Avalon Web Services LLC · Avalon CloudSec (cloudsec.awservices.org) · Last updated: September 2026
What we collect
Avalon CloudSec reads security and configuration telemetry from your Microsoft 365 tenant (and, if you enable it, your Azure subscription) using read-only permissions that your administrator grants during onboarding. Collected telemetry includes: Microsoft Secure Score and improvement actions; Defender incident and alert metadata; Entra identity-risk signals; Intune device inventory and compliance state; Microsoft 365 service health; license subscriptions and assignments; Conditional Access policy configuration; per-user MFA registration status; your tenant's enterprise-application and OAuth-grant inventory (application names, publishers, permissions, and credential expiry metadata — never credential values); a user directory inventory (name, sign-in address, account status, assigned licenses, and — where your tenant is licensed for it — last sign-in timestamps); Microsoft 365 usage reports (per-user last-activity dates per service, subject to your tenant's report-privacy settings); and, for linked Azure subscriptions, Defender for Cloud assessments, resource inventory summaries, and cost totals.
What we do not collect
We do not read email content, file or document contents, chat or meeting content, or user passwords. Our Microsoft integration is read-only: CloudSec holds no permissions that can change your tenant, and it never performs remediation — dashboards deep-link you to Microsoft's own admin portals for that.
Why we collect it
Solely to provide the service: security-posture dashboards, findings and alerting, application and AI governance, license optimization analytics, compliance evidence, and reports for your organization. We do not sell customer data, use it for advertising, or train machine-learning models on it.
Where it is processed and stored
Collected telemetry is transferred over TLS and persisted in Avalon CloudSec's database so we can show trends and history — it is a copy of security metadata held outside your Microsoft tenant, which is why we describe the product as read-only rather than "data never leaves Microsoft". The service runs on Vercel (application hosting) and Supabase (managed PostgreSQL database) infrastructure in the United States. These providers act as our subprocessors for hosting and storage.
Isolation and access control
Every record is keyed to your organization, and database row-level security enforces that your users can only ever read your organization's rows — isolation is enforced at the database layer, not just in application code. Sign-in uses per-user accounts with TOTP multi-factor authentication (mandatory for administrators), and Avalon staff access is role-restricted and recorded in an audit log.
Credential handling
The Microsoft app credential you provide for collection is encrypted at rest with AES-256-GCM; the encryption key is stored in the application's runtime configuration, separate from the database that holds the encrypted values. Credentials are never displayed back in the browser, never written to logs, and credential rotation is audit-logged.
Retention and deletion
Telemetry is retained on a tiered schedule so trends can be computed without accumulating indefinitely: full-resolution snapshots are kept for roughly 30 days, then automatically thinned to one snapshot per day, and daily history is deleted after 12 months. When an organization offboards, its access is disabled immediately and its data is deleted automatically after a 90-day retention window. Provider-managed database backups age out on a rolling schedule and are not used to restore offboarded customer data. You may request earlier deletion at any time via the contact below.
Cookies and analytics
Essential cookies keep you securely signed in — the service does not work without them. We currently load no third-party analytics or advertising scripts. If optional analytics are introduced, they will load only after you accept them via the cookie banner, and this policy will be updated first.
Compliance status
Avalon CloudSec's compliance module presents observed technical evidence and customer attestations; it is a technical assessment, not a certification. Avalon Web Services LLC does not currently claim SOC 2, ISO 27001, or HIPAA certification for the CloudSec service itself. If your organization requires a Business Associate Agreement or specific contractual terms, contact us before onboarding.
Contact
Privacy questions, data-subject requests, or deletion requests: support@awservices.org
Microsoft, Microsoft 365, Azure, Entra, Intune, and Defender are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not affiliated with or endorsed by Microsoft.