Trust Center
Security, Privacy, and Terms
Security
Both products read your Microsoft 365 tenant and never write to it. What follows is what each one does with that access — and, just as importantly, what neither will claim.
Shared across both products
Read-Only by Construction
Both applications request read-only Microsoft Graph permissions and hold no write scopes at all. They cannot create, modify, or delete anything in your tenant. Consent is granted once by your Global Administrator and can be revoked by you at any time.
Certificate-Based Authentication
Authentication uses an X.509 certificate rather than a stored client secret. No client secrets are kept on your machine, and the private key never leaves it.
Your Tenant Data Stays Local
Scans run from a Windows desktop application on a machine you control. Reports, evidence, and history are written to your own disk. The only network calls a scan makes are read-only requests to Microsoft.
TenantSentinel Recon
Quantified Risk Posture
Every scan produces a TenantSentinel Analysis Score with weighted sub-scores across identity, access control, and privileged security — so leadership sees exactly where exposure is highest. Scoring weights, penalty logic, and compliance framework mappings are fully documented on the Assessment Methodology page.
10-Tab Executive Report
MFA coverage, Conditional Access validation, privileged role risk, enterprise app permissions, licensing cost analysis, security gaps, risk scenarios, baseline compliance, and historical trending — all in one self-contained HTML file.
Actionable Remediation
Every risk scenario includes remediation runbooks with portal steps, PowerShell commands, verification steps, effort estimates, and/or rollback notes. No guessing what to do next.
Drift Detection & Trending
Repeat scans track your health score over time with automatic drift markers. Regressions in MFA coverage, new risk scenarios, and score drops are flagged so nothing slips through between assessments.
Desktop App Security
The Recon desktop app runs with context isolation and sandboxed rendering—no Node.js access from the UI layer. All system operations go through a locked-down IPC bridge, and reports render inside a sandboxed iframe.
TenantSentinel Proof
Tamper-Evident Evidence Ledger
Each scan appends a SHA-256 hash-chained entry recording the evidence it collected. Altering an evidence file changes its hash and breaks the chain; verification identifies the exact entry where it diverges. Evidence you can check beats evidence you have to trust.
All 110 Controls, Nothing Hidden
Every NIST SP 800-171 Rev 2 control appears in the output. The 38 organizational controls a tenant scan cannot evidence are printed with an explicit reason rather than quietly omitted, and the nine controls inherited from Microsoft are labeled as such.
Attestation Stays in Its Own Lane
An operator may attest only to controls the scan marked as needing manual review or as organizational, recording their name, role, a written justification, and a supporting file whose hash is written into the ledger. An attestation can never override a control the tool actually tested and found not implemented, and tool-verified findings are never merged with self-attested ones.
It Never False-Fails
When a check cannot run — an unlicensed workload, a permission not granted, an API that did not answer — the control degrades to needs manual review rather than being marked failed. A control is reported as not implemented only when a check ran and found it missing.
The Score Is an Estimate
Because a technical scan cannot assess every control, Proof reports a scoring range rather than a single certain number, and labels it every time it appears as an estimate and not a certified SPRS score. TenantSentinel is not a C3PAO and does not certify; Proof supports assessment preparation.
Privacy & Data Handling
Your Microsoft 365 tenant data never leaves your machine. Scans run locally and results are written to your own disk—never to our servers.
The licensing server stores only what is required to operate your license: the key, your Entra tenant ID, certificate thumbprint, activation date, and company name. No scan data, report content, or tenant user information is ever transmitted to or stored by TenantSentinel. We use a single subprocessor, Resend, to deliver license keys and transactional email.
Terms & Compliance
TenantSentinel products are read-only, licensed for tenants you own or manage, and provided without warranty.
Our tools operate on the minimum read-only Microsoft Graph permissions required and cannot modify your tenant configuration. We align internal controls with SOC 2 Type II principles as we mature toward formal certification. TenantSentinel is not a CMMC Third-Party Assessment Organization (C3PAO) and does not perform certifications—our output supports assessment preparation and does not constitute legal, regulatory, or audit advice.