Privacy Policy

Last updated: August 3, 2026

TrueRock.AI (“TrueRock”, “we”) provides Microsoft 365 security and AI-governance tooling to Managed Service Providers. This policy explains what we collect, what we keep, and for how long.

1. This website

We use Microsoft Clarity to understand how this site is used. Clarity sets first-party cookies (_clck, _clsk) to recognize a returning visit, and it records pointer movement, clicks and scrolling to build heatmaps and session replays.

The text on the page is masked. We run Clarity in its strict masking mode, so the words you read and anything you type are replaced with placeholder characters before the recording leaves your browser. The one exception is the name of a demo you open (for example “Shadow AI”), which we record as a label so we know which films people watch. We do not use advertising cookies, we do not sell data, and we do not use this tooling to identify you.

Clarity is operated by Microsoft, which processes this data as our service provider under the Microsoft Privacy Statement. Microsoft keeps recordings for about 30 days (a small sample for up to nine months) and heatmap data for up to nine months. To opt out, block clarity.ms in your browser or with an extension; most tracker-blocking extensions do this already.

Our web host keeps standard server logs, including IP address, for operational and security purposes for a limited period.

2. The assessment

If you run a TrueRock assessment, a Microsoft 365 Global Administrator grants us read-only access to that tenant.

What we read

Configuration and governance data only — application registrations and the permissions granted to them, who approved them and when, sign-in activity for applications, user and administrator counts, multi-factor authentication registration status, Conditional Access policies, directory roles, subscribed licenses, and tenant-level sharing settings.

What we never read

We do not read the contents of your documents, files, email, chats or messages. The permissions we request do not permit it. We do not have write access: we cannot change anything in your tenant.

What we keep

Where it is stored

In the United States. If you are outside the United States, your data will be transferred to and stored in the US.

Who can see it

No TrueRock personnel access assessment findings by default. Support access is possible where necessary and is logged.

Revoking access

You may revoke our access at any time from the Microsoft Entra admin centre by removing the TrueRock application from your enterprise applications. Revocation stops all future access immediately; use the delete link to remove data already collected.

3. Contact and requests

To request deletion, ask what we hold, or raise a concern, email hello@truerock.ai.

4. Changes

We will post changes on this page and update the date above.