Security and privacy¶
A compliance tool shouldn't add risk. Here's how Trimtab protects your clients.
Read-only by design¶
- Lookout only reads settings. No check changes the system.
- The Microsoft 365 connection uses read-only application permissions. See what Trimtab can access.
Your organization's data¶
Every Trimtab organization, whether an MSP or a business using Trimtab directly, has its own database. Your clients, devices, tenants, findings, team, and activity log live only there.
- People in one organization can't see, search, or sign in to another. The Bridge only opens your organization's database for your session.
- Device credentials, enrollment keys, and invite links each belong to the organization that issued them, and only reach that organization's data.
- Each sign-in name (usually an email address) belongs to one organization.
- Trimtab staff can see each organization's counts (clients, devices, tenants, and overdue devices) so we can support you. We can't see your findings or your clients' names from our console.
- Need your own server? Ask about a dedicated deployment, which runs Trimtab for your organization on separate infrastructure.
Devices¶
- Each device has its own credential, issued at enrollment, encrypted with Windows DPAPI, and stored where only SYSTEM and Administrators can read it.
- Enrollment keys are stored only as fingerprints, and can be revoked without affecting enrolled devices.
- Lookout makes outbound HTTPS connections only. It opens no ports and accepts no commands.
- Revoking a device in the Bridge immediately stops it from reporting.
Microsoft 365¶
- Trimtab authenticates to tenants with a certificate, not a shared secret.
- Each tenant approves access through Microsoft's own admin consent screen, and can remove it at any time by deleting the Trimtab app from Enterprise applications.
- Trimtab doesn't read email, files, chats, or calendars.
The Bridge¶
- Every sign-in needs a password and an authenticator code. Codes can't be reused.
- Repeated failed sign-ins are rate limited.
- All traffic uses HTTPS, and sessions expire after 8 hours.
- Data is stored in Microsoft Azure data centers in the United States.
What's collected¶
| Source | Collected |
|---|---|
| Devices | Computer name, manufacturer, model, serial number, domain or Entra tenant, Windows version, security settings, names of accounts with local admin rights, latest security update, and each check's evidence |
| Microsoft 365 | Organization name, tenant ID, domains, security and sharing settings, names of Global Administrators, users not registered for MFA, inactive accounts, external forwarding addresses, Secure Score, and DMARC records |
Passwords, documents, email content, and browsing activity are never collected. The full policy is at gettrimtab.com/privacy.
Reporting a security issue¶
Email hello@gettrimtab.com with the subject Security.