Security overview
TrueNorth Exposure Scan is designed so the worst-case exposure is a list of file names, never file contents.
Access model
- Multitenant Microsoft Entra app, application permissions, admin consent only. No user passwords are handled.
- Read-only Microsoft Graph permissions:
Sites.Read.All,Directory.Read.All,AuditLog.Read.All,SharePointTenantSettings.Read.All. - Write calls are blocked in code. The Graph client refuses POST, PATCH, PUT and DELETE.
- Revocation: delete the enterprise application in Entra ID. Access ends immediately.
Data handling
- Collected: site, folder and file names and paths; sharing-link type, scope and expiry; the email addresses a file is shared with; guest account names and dates; admin role membership; licence counts; tenant sharing settings.
- Never collected: file contents, email, chat, calendar, passwords.
- Retention: 90 days by default; deleted within 30 days of cancellation.
- Hosting: Microsoft Azure, United States. TLS 1.2+ in transit, encryption at rest, secrets in Azure Key Vault.
Operations
- MFA and least privilege on every administrative account.
- Critical patches within 7 days, all others within 30.
- Incident notification to customers within 72 hours of confirmation.
- Contact: security@truenorthdatashield.com