Privacy notice
How the portal handles data.
Billed via Microsoft Marketplace
Last updated: 2026-05-10
This portal is designed to collect only the minimum inputs required to produce an assessment run and its output files.
Quick links
Data you provide
- Scenario selection and assessment parameters (e.g., target domain).
- Contact details when required to generate an assessment.
- Optional notes you enter (avoid secrets).
Personal data categories can include business contact details (such as work email), organization identifiers, and operational request metadata needed to deliver your requested assessment.
Generated data
- Run status/progress metadata.
- Generated report/result files made available for download.
How we use and share data
- We use data to operate the portal, run requested assessments, generate deliverables, and provide support.
- Access is limited to authorized personnel and approved subprocessors required to provide the service.
- We do not sell customer personal data.
- Where required by law, we may disclose limited data to competent authorities.
See Subprocessors and Data Processing Agreementfor processing roles and commitments.
Evidence uploads
When enabled for a scenario, evidence uploads are performed directly from your browser to your designated storage workspace. The portal UI does not store uploaded evidence files in the application backend. Generated output files and the operational metadata needed to deliver the service are handled separately under the retention window below.
Cookies and browser storage
- This portal uses browser storage (localStorage/sessionStorage) for functional settings such as UI preferences and run continuity.
- We do not use browser cookies for advertising purposes in this portal experience.
- If operational cookies are introduced in future releases, this page will be updated with their purpose and lifetime.
Retention
- Request metadata: 365 days.
- Audit trail: 730 days.
- Generated output files created for your request: up to 365 days.
These windows apply to run metadata, audit records, and generated output files. They do not mean the portal stores uploaded evidence files in the application backend. The windows mirror the retention commitments in the Data Processing Agreement. If you need earlier removal or an account-level data deletion review, use the support contact referenced by your engagement.
Security safeguards
- Encryption in transit and at rest for service data.
- Role-based access controls and least-privilege operational access.
- Logging and audit trail controls for security and support operations.
Additional details are available on the Security page.
Your rights and requests
You can request access, correction, deletion, or export of applicable personal data through the engagement support channel.
See Data subject requests for request handling guidance.
Payment data
Billing for this service is performed by Microsoft through the Microsoft Commercial Marketplace. Microsoft, not MSC/LuiT, processes payment instruments, taxes, invoices, and refunds for the subscription. The portal receives only the subscription identifier and metering events required to operate your plan.
Contact
For privacy questions or data requests, use the support contact referenced by your engagement or the support channel on Support.