Privacy Policy
Last updated: August 3, 2026
TrueRock.AI (“TrueRock”, “we”) provides Microsoft 365 security and AI-governance tooling to Managed Service Providers. This policy explains what we collect, what we keep, and for how long.
1. This website
We use Microsoft Clarity to understand how this site is used. Clarity sets
first-party cookies (_clck, _clsk) to recognize a returning visit, and
it records pointer movement, clicks and scrolling to build heatmaps and session replays.
The text on the page is masked. We run Clarity in its strict masking mode, so the words you read and anything you type are replaced with placeholder characters before the recording leaves your browser. The one exception is the name of a demo you open (for example “Shadow AI”), which we record as a label so we know which films people watch. We do not use advertising cookies, we do not sell data, and we do not use this tooling to identify you.
Clarity is operated by Microsoft, which processes this data as our service provider under the
Microsoft Privacy Statement.
Microsoft keeps recordings for about 30 days (a small sample for up to nine months) and
heatmap data for up to nine months. To opt out, block clarity.ms in your browser or
with an extension; most tracker-blocking extensions do this already.
Our web host keeps standard server logs, including IP address, for operational and security purposes for a limited period.
2. The assessment
If you run a TrueRock assessment, a Microsoft 365 Global Administrator grants us read-only access to that tenant.
What we read
Configuration and governance data only — application registrations and the permissions granted to them, who approved them and when, sign-in activity for applications, user and administrator counts, multi-factor authentication registration status, Conditional Access policies, directory roles, subscribed licenses, and tenant-level sharing settings.
What we never read
We do not read the contents of your documents, files, email, chats or messages. The permissions we request do not permit it. We do not have write access: we cannot change anything in your tenant.
What we keep
- We keep your assessment findings — and only the specific values shown in those findings — for 30 days, after which they are permanently deleted. A delete link is provided with your results; you may delete sooner at any time, without contacting us.
- We keep aggregate statistics containing no tenant identifier, no domain and no personal data — for example, how many tenants of a given size have multi-factor authentication enforced. These are recorded when your assessment runs, cannot be traced back to you, and are not deleted with your assessment.
- If you gave us an email address, we keep it with the domain assessed and a short summary of the outcome, so that we can follow up with you about your results. We keep this for 12 months. Ask us to delete it at any time using the details below, and tell us if you would rather we did not contact you — we will not.
- We keep an operational record that an assessment was run, for which tenant and when, to prevent abuse and enforce rate limits. It is retained separately from your findings.
- If your tenant is subsequently managed by a provider using the TrueRock platform under a signed agreement, that agreement governs retention from that point forward.
Where it is stored
In the United States. If you are outside the United States, your data will be transferred to and stored in the US.
Who can see it
No TrueRock personnel access assessment findings by default. Support access is possible where necessary and is logged.
Revoking access
You may revoke our access at any time from the Microsoft Entra admin centre by removing the TrueRock application from your enterprise applications. Revocation stops all future access immediately; use the delete link to remove data already collected.
3. Contact and requests
To request deletion, ask what we hold, or raise a concern, email hello@truerock.ai.
4. Changes
We will post changes on this page and update the date above.