It reads your security posture. It doesn't keep it.
This notice covers the Avalon CloudSec Security Intelligence MCP service at mcp.awservices.org — what it reads in your Microsoft 365 tenant, what it stores, for how long, and how you end that access. For the awservices.org website and consulting engagements, see the main privacy policy.
Last reviewed · September 2026
01 · Summary
The short version
The service reads security-posture information from your Microsoft 365 tenant and returns it to an AI assistant you control. It is read-only — it cannot change anything in your tenant. It does not store your security data. It keeps operational metadata about who called which tool, and a cryptographic hash of what was returned, so access can be audited without the underlying data being retained.
02 · Access
What the service can read
Access is granted once, by an administrator of your tenant, through Microsoft admin consent to the Avalon CloudSec Graph application. That application requests read permissions only:
| IdentityRiskyUser.Read.All | Risky-user counts and risk levels |
| IdentityRiskEvent.Read.All | Risk-detection counts |
| AuditLog.Read.All | Risky sign-in counts |
| Reports.Read.All | MFA registration coverage |
| RoleManagement.Read.Directory | Directory role assignments |
| RoleEligibilitySchedule.Read.Directory | PIM-eligible role assignments |
| DeviceManagementManagedDevices.Read.All | Intune device compliance and staleness |
| Policy.Read.All | Conditional Access policy state |
| SecurityEvents.Read.All | Microsoft Secure Score |
| SecurityIncident.Read.All | Defender XDR incident counts |
There is no write, remediation, user-disable, device-wipe, policy-update or incident-resolution capability anywhere in the service. It cannot reach any Microsoft Graph endpoint other than the ones fixed in its code: no tool accepts a URL, a Graph path, or a free-form query.
It does not access mailbox contents, Teams conversations, SharePoint or OneDrive files, or any document content.
03 · Personal data
Identifiers are off by default
Results are counts and states by default. Fields that identify a person, device or incident — user principal name, display name, object ID, device name, incident title — are removed before the result is returned, unless the caller explicitly asks for them on that specific call.
That choice is made per call by the person operating the AI assistant. It is never implied by their role, their plan, or their tenant. When identifiers are requested, they are returned to your calling application and are not retained by us.
04 · Retention
What we store, and for how long
| Application traces | 30 days | Request timing and status. No payloads. |
| Authorization events | 90 days | Pseudonymous principal identifier, client ID, allow or deny, and a coarse reason. |
| Tool audit records | 90 days | Which tool, which tenant, outcome, duration, record count, and a SHA-256 hash of the returned document. |
| Tenant and entitlement records | Life of the customer relationship | Your tenant ID, display name, plan, and which people are entitled to which tenants. |
| Certification evidence | Certified version plus one successor | Schemas and test records. No customer data. |
The principal identifier in audit records is a salted SHA-256 hash, not your users' Entra object IDs. The salt is a per-deployment secret, so a hash from this deployment cannot be correlated with one from anywhere else, and an audit log on its own cannot be reversed to a named person.
05 · Never stored
What we do not keep, at all
- The security data returned by any tool — the results themselves.
- The prompts or questions put to the AI assistant.
- Access tokens, refresh tokens, Microsoft Entra ID tokens, or Microsoft Graph tokens.
- Microsoft Graph response payloads.
- Your users' raw Entra object IDs.
Log redaction is enforced structurally at the logging layer rather than left to individual code paths, and is covered by an automated test that fails the build if a token or a payload field reaches the audit trail.
06 · AI
No model of ours sees your data
The service performs no AI inference. It returns structured data to whichever AI assistant you operate — your Claude, your Copilot, or another compatible client. Your security telemetry is not sent to an Avalon-hosted model, and not by us to any third-party model provider. What your own AI client does with the data it receives is governed by your agreement with that provider.
07 · Processing
Where it runs
The service runs in Microsoft Azure, in the East US 2 region. Microsoft Azure is our only sub-processor for hosting, logging and secret storage. Data read from your tenant travels from Microsoft Graph to the service and on to your AI client; it is not copied to any other party.
Signing in federates to Microsoft Entra ID. We receive your object ID, tenant ID and sign-in name from Microsoft in order to establish who you are and which tenants you may query. We do not receive or store your password or your second factor.
08 · Revocation
Ending access
You can end access at any time, and it takes effect immediately.
- Revoke it yourself. Microsoft Entra admin centre → Enterprise applications → Avalon CloudSec Graph → Properties → Delete. This removes our ability to read your tenant regardless of anything on our side.
- Ask us to offboard you. We disable the tenant record, revoke all entitlements and refresh tokens, and confirm in writing.
Because no security data is retained, offboarding leaves only the audit metadata described above, which ages out on its stated schedule.
09 · Your rights
Asking what we hold
To ask what audit metadata we hold about a principal, or to request its deletion, email us. We respond within 30 days. Audit records are pseudonymous by design, so identifying the records relating to a particular person needs your help to confirm which principal is meant.
10 · Changes
When this notice changes
Material changes are notified to the administrative contact for each customer tenant at least 30 days before they take effect. The date at the top of this page always reflects the current version.
11 · Contact
How to reach us
Questions about this notice or your data? Email support@awservices.org. For security-specific concerns, including vulnerability reports, use security@awservices.org.