Skip to content

Security and privacy

A compliance tool shouldn't add risk. Here's how Trimtab protects your clients.

Read-only by design

  • Lookout only reads settings. No check changes the system.
  • The Microsoft 365 connection uses read-only application permissions. See what Trimtab can access.

Your organization's data

Every Trimtab organization, whether an MSP or a business using Trimtab directly, has its own database. Your clients, devices, tenants, findings, team, and activity log live only there.

  • People in one organization can't see, search, or sign in to another. The Bridge only opens your organization's database for your session.
  • Device credentials, enrollment keys, and invite links each belong to the organization that issued them, and only reach that organization's data.
  • Each sign-in name (usually an email address) belongs to one organization.
  • Trimtab staff can see each organization's counts (clients, devices, tenants, and overdue devices) so we can support you. We can't see your findings or your clients' names from our console.
  • Need your own server? Ask about a dedicated deployment, which runs Trimtab for your organization on separate infrastructure.

Devices

  • Each device has its own credential, issued at enrollment, encrypted with Windows DPAPI, and stored where only SYSTEM and Administrators can read it.
  • Enrollment keys are stored only as fingerprints, and can be revoked without affecting enrolled devices.
  • Lookout makes outbound HTTPS connections only. It opens no ports and accepts no commands.
  • Revoking a device in the Bridge immediately stops it from reporting.

Microsoft 365

  • Trimtab authenticates to tenants with a certificate, not a shared secret.
  • Each tenant approves access through Microsoft's own admin consent screen, and can remove it at any time by deleting the Trimtab app from Enterprise applications.
  • Trimtab doesn't read email, files, chats, or calendars.

The Bridge

  • Every sign-in needs a password and an authenticator code. Codes can't be reused.
  • Repeated failed sign-ins are rate limited.
  • All traffic uses HTTPS, and sessions expire after 8 hours.
  • Data is stored in Microsoft Azure data centers in the United States.

What's collected

Source Collected
Devices Computer name, manufacturer, model, serial number, domain or Entra tenant, Windows version, security settings, names of accounts with local admin rights, latest security update, and each check's evidence
Microsoft 365 Organization name, tenant ID, domains, security and sharing settings, names of Global Administrators, users not registered for MFA, inactive accounts, external forwarding addresses, Secure Score, and DMARC records

Passwords, documents, email content, and browsing activity are never collected. The full policy is at gettrimtab.com/privacy.

Reporting a security issue

Email hello@gettrimtab.com with the subject Security.