Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security
Avalon CloudSec MCP · Privacy

It reads your security posture. It doesn't keep it.

This notice covers the Avalon CloudSec Security Intelligence MCP service at mcp.awservices.org — what it reads in your Microsoft 365 tenant, what it stores, for how long, and how you end that access. For the awservices.org website and consulting engagements, see the main privacy policy.

Last reviewed · September 2026

01 · Summary

The short version

The service reads security-posture information from your Microsoft 365 tenant and returns it to an AI assistant you control. It is read-only — it cannot change anything in your tenant. It does not store your security data. It keeps operational metadata about who called which tool, and a cryptographic hash of what was returned, so access can be audited without the underlying data being retained.

02 · Access

What the service can read

Access is granted once, by an administrator of your tenant, through Microsoft admin consent to the Avalon CloudSec Graph application. That application requests read permissions only:

IdentityRiskyUser.Read.AllRisky-user counts and risk levels
IdentityRiskEvent.Read.AllRisk-detection counts
AuditLog.Read.AllRisky sign-in counts
Reports.Read.AllMFA registration coverage
RoleManagement.Read.DirectoryDirectory role assignments
RoleEligibilitySchedule.Read.DirectoryPIM-eligible role assignments
DeviceManagementManagedDevices.Read.AllIntune device compliance and staleness
Policy.Read.AllConditional Access policy state
SecurityEvents.Read.AllMicrosoft Secure Score
SecurityIncident.Read.AllDefender XDR incident counts

There is no write, remediation, user-disable, device-wipe, policy-update or incident-resolution capability anywhere in the service. It cannot reach any Microsoft Graph endpoint other than the ones fixed in its code: no tool accepts a URL, a Graph path, or a free-form query.

It does not access mailbox contents, Teams conversations, SharePoint or OneDrive files, or any document content.

03 · Personal data

Identifiers are off by default

Results are counts and states by default. Fields that identify a person, device or incident — user principal name, display name, object ID, device name, incident title — are removed before the result is returned, unless the caller explicitly asks for them on that specific call.

That choice is made per call by the person operating the AI assistant. It is never implied by their role, their plan, or their tenant. When identifiers are requested, they are returned to your calling application and are not retained by us.

04 · Retention

What we store, and for how long

Application traces30 daysRequest timing and status. No payloads.
Authorization events90 daysPseudonymous principal identifier, client ID, allow or deny, and a coarse reason.
Tool audit records90 daysWhich tool, which tenant, outcome, duration, record count, and a SHA-256 hash of the returned document.
Tenant and entitlement recordsLife of the customer relationshipYour tenant ID, display name, plan, and which people are entitled to which tenants.
Certification evidenceCertified version plus one successorSchemas and test records. No customer data.

The principal identifier in audit records is a salted SHA-256 hash, not your users' Entra object IDs. The salt is a per-deployment secret, so a hash from this deployment cannot be correlated with one from anywhere else, and an audit log on its own cannot be reversed to a named person.

05 · Never stored

What we do not keep, at all

  • The security data returned by any tool — the results themselves.
  • The prompts or questions put to the AI assistant.
  • Access tokens, refresh tokens, Microsoft Entra ID tokens, or Microsoft Graph tokens.
  • Microsoft Graph response payloads.
  • Your users' raw Entra object IDs.

Log redaction is enforced structurally at the logging layer rather than left to individual code paths, and is covered by an automated test that fails the build if a token or a payload field reaches the audit trail.

06 · AI

No model of ours sees your data

The service performs no AI inference. It returns structured data to whichever AI assistant you operate — your Claude, your Copilot, or another compatible client. Your security telemetry is not sent to an Avalon-hosted model, and not by us to any third-party model provider. What your own AI client does with the data it receives is governed by your agreement with that provider.

07 · Processing

Where it runs

The service runs in Microsoft Azure, in the East US 2 region. Microsoft Azure is our only sub-processor for hosting, logging and secret storage. Data read from your tenant travels from Microsoft Graph to the service and on to your AI client; it is not copied to any other party.

Signing in federates to Microsoft Entra ID. We receive your object ID, tenant ID and sign-in name from Microsoft in order to establish who you are and which tenants you may query. We do not receive or store your password or your second factor.

08 · Revocation

Ending access

You can end access at any time, and it takes effect immediately.

  • Revoke it yourself. Microsoft Entra admin centre → Enterprise applications → Avalon CloudSec Graph → Properties → Delete. This removes our ability to read your tenant regardless of anything on our side.
  • Ask us to offboard you. We disable the tenant record, revoke all entitlements and refresh tokens, and confirm in writing.

Because no security data is retained, offboarding leaves only the audit metadata described above, which ages out on its stated schedule.

09 · Your rights

Asking what we hold

To ask what audit metadata we hold about a principal, or to request its deletion, email us. We respond within 30 days. Audit records are pseudonymous by design, so identifying the records relating to a particular person needs your help to confirm which principal is meant.

10 · Changes

When this notice changes

Material changes are notified to the administrative contact for each customer tenant at least 30 days before they take effect. The date at the top of this page always reflects the current version.

11 · Contact

How to reach us

Questions about this notice or your data? Email support@awservices.org. For security-specific concerns, including vulnerability reports, use security@awservices.org.