Trust Center
Everything your security team needs, in one place.
LicenseMeter reads license and directory metadata from your Microsoft 365 tenant, so trust is the whole product. This page brings together how we access data, where it lives, who processes it, and the documents that back it up. Everything here is sourced from the same agreements we sign with you.
At a glance
Read-only access
Application permissions are read-only without exception. We can never change anything in your tenant.
EU data residency
Customer data is stored in the EU, in a Supabase Postgres database on AWS eu-central-1 (Frankfurt).
Delete on disconnect
Disconnecting a workspace deletes all synced data immediately and irreversibly.
GDPR DPA, pre-signed
An Art. 28 GDPR data processing agreement is part of every subscription, downloadable and pre-signed.
Encrypted throughout
TLS in transit, AES-256 at rest, and AES-256-GCM at the app layer for any third-party credentials.
Cookieless analytics
No tracking or marketing cookies, no consent banner. Aggregated, IP-free Vercel Web Analytics.
Where your data lives
These are the sub-processors LicenseMeter engages, with their processing location and the transfer mechanism that covers it. The list is rendered from the binding Data Processing Agreement, so it is always the same list you sign.
Application hosting and content delivery
- Location:
- EU (Frankfurt function region)
- Transfer:
- EU processing; SCCs for any support access from outside the EU
Managed PostgreSQL database (primary data store)
- Location:
- EU (AWS eu-central-1, Frankfurt)
- Transfer:
- EU processing; SCCs for any support access from outside the EU
Identity platform (sign-in, admin consent) and Microsoft Graph API
- Location:
- EU Data Boundary; US fallback
- Transfer:
- EU Standard Contractual Clauses (Microsoft Products and Services DPA)
Authentication and user identity management (AuthKit sign-in), where enabled
- Location:
- US
- Transfer:
- EU Standard Contractual Clauses (WorkOS DPA)
Billing and subscription management (for paid plans)
- Location:
- EU and US
- Transfer:
- EU Standard Contractual Clauses (Stripe DPA); retains invoice data to meet statutory tax-retention duties
Transactional and notification email delivery
- Location:
- EU (Ireland region)
- Transfer:
- EU processing; SCCs where applicable
Optional source systems you connect (Adobe, Zoom, Atlassian, Salesforce, OpenAI, Anthropic) and any CSV member lists you import (ChatGPT, Claude) are data sources, not sub-processors: we read from them on your behalf and disclose no personal data to them beyond the authenticated read request. The definitive list is Annex 3 of the DPA.
How access works
A Global Administrator grants consent once, through Microsoft's standard admin-consent dialog, for application permissions that are read-only without exception. There is no service account, agent or mailbox plugin in your tenant, and you can revoke the application in Entra ID at any time, independently of us. Usage reports are consumed as counts and last-activity dates only: metadata, never content.
The Security overview lists every requested scope, what is stored, and how to delegate the consent without standing Global Administrator rights.
Security measures
Access to a workspace is invite-based and role-based (owner, admin, viewer); sign-in uses OpenID Connect with PKCE and signed, httpOnly, short-lived session cookies. Data is encrypted in transit (TLS, HSTS) and at rest (AES-256), with bring-your-own connector credentials additionally encrypted at the application layer (AES-256-GCM). Tenants are logically separated with row-level security, state-changing requests are CSRF-protected and rate-limited, and a per-workspace audit log records exports and administrative actions.
The full technical and organizational measures are Annex 2 of the DPA.
Data lifecycle
Data is collected only by the read-only sync, retained only while your tenant is connected, and deleted on disconnect. Disconnecting a workspace (Settings → Danger zone) deletes all synced data immediately and irreversibly: users, findings, prices, history and the audit log. Revoking the enterprise application in your Entra ID additionally cuts our access at the source. The one exception is the billing provider, which retains invoice data for the period required by statutory tax law. See the Privacy Policy for retention detail and your data subject rights.
Certifications and status
Our sub-processors are selected for documented security postures and are bound by data processing agreements; the major infrastructure providers above maintain SOC 2 and/or ISO 27001 certifications, whose reports we can reference in a security review. LicenseMeter itself does not yet hold its own SOC 2 / ISO 27001 attestation.
Microsoft publisher verification for the LicenseMeter app registrations is in progress. Until it completes, the consent dialog shows the apps as unverified; Microsoft displays the current verification status directly in the dialog, so your admin can always confirm it independently.
Documents
Security overview
Exactly what is granted, stored and how to leave. Read-only scopes, delegated consent, deletion.
Data Processing Agreement
Art. 28 GDPR DPA / AVV, pre-signed. Download in English or German with the full subprocessor annex and TOMs.
Privacy Policy
What we process, on what legal basis, for how long, and the data subject rights that apply.
Terms
The B2B service agreement. The DPA prevails over the Terms on anything to do with data processing.
Cookie policy
The functional cookies we set, why, and how long they live. No tracking cookies.
FAQ
Plain-language answers to the questions security and identity teams ask most often.
Questions
Security reviews, pentest coordination and vendor questionnaires: customer-care@ugurlabs.odoo.com.