Skip to main content
AzureProof Docs
  • Quick start
  • Connecting your Azure tenant
  • Understanding your score
  • Your first audit
  • How SOC2 evidence works
  • Control categories explained
  • Pass / Warn / Fail criteria
  • Evidence retention policy
  • Access controls (CC6.x)
  • Threat detection (CC7.x)
  • Change management (CC8.x)
  • Availability (A1.x)
  • Microsoft Graph
  • Defender for Cloud
  • Activity Log
  • Future: AWS, GCP
  • Our security model
  • Permissions we request
  • Data we store (and don't store)
  • Encryption at rest
  • SOC2 status
  • Responsible disclosure
  • Authentication
  • Endpoints
  • Webhooks

25 pages

security

Data we store (and don't store)

Inventory of what's persisted and what's discarded after a run.

We store

  • Control evaluation results
  • Resource IDs and names
  • Run metadata and scores

We don't store

  • Secrets, keys, or connection strings
  • User data inside your resources
  • Network traffic
Previous
Permissions we request
Next
Encryption at rest