VERSION 1.2 · EFFECTIVE SEPTEMBER 19, 2026

SCOUTz Microsoft 365 Review application — Terms of Use

Publisher: SCOUTz LLC.

Plain-words summary

SCOUTz reads settings, not content. With your permission it reads how your Microsoft 365 tenant is configured: who holds admin roles, which applications have been granted access, what licences are assigned, what sign-in policies exist, which devices are enrolled, and what Microsoft itself recommends. It never reads mail, documents, files, chats, meetings or Copilot prompts, and it never asks for the permissions that could. It changes nothing. You can revoke it at any time from your Microsoft admin centre, and the review your provider ran is deleted 30 days after it completes unless your provider pins it as a baseline with your knowledge.

Parties

These terms are between SCOUTz LLC ("SCOUTz", "we") and the organisation whose administrator or user grants the SCOUTz application access to its Microsoft 365 tenant ("you"). Your managed service provider ("your provider") runs the review on your behalf under a separate agreement between you and your provider.

Publisher of record

The application is registered in Microsoft's directory under AEGITz LLC, an affiliate of SCOUTz LLC, which appears as the verified publisher on Microsoft's consent screen. SCOUTz LLC operates the application and is the party to these terms. When the registration moves to SCOUTz LLC, a new consent will be requested and these terms will be updated.

What the application does

The application reads configuration and metadata from your Microsoft 365 tenant through the Microsoft Graph API, using read-only permissions only, to produce a security review for your provider. It does not create, modify or delete anything in your tenant.

What it does not do

The application does not request, and will not accept, permissions that read the content of mail, documents, files, chats, meetings or Copilot interactions. If a consent grant carries any such permission, the application refuses the grant and reads nothing.

Levels of access

Access is offered at one of three levels, each described on its own consent page. A level is offered only when it is available in the product.

  1. User sign-in. One user signs in. The application reads basic organisation details, that user's own licence, and the directory's basic user list. It reads no administrative data.
  2. Administrator session. An administrator signs in. The application reads identity, roles, application grants, licences and policies under that administrator's own permissions for the duration of the session only. Access ends when the session token expires, within about one hour. Nothing is stored that could renew it.
  3. Tenant-wide read-only consent. A Global Administrator or Privileged Role Administrator grants read-only application permissions for a full review. The permission list is shown on Microsoft's consent screen and on ours.

Credentials and tokens

The application stores no Microsoft access token and no refresh token for your tenant. Access is obtained for each review from the consent standing in your own tenant, held in memory for the duration of the review, and discarded. There is no stored credential that could be used outside a review.

Revocation

You may revoke the application at any time in the Microsoft Entra admin centre (Enterprise applications → SCOUTz → Permissions) or by asking your provider. Revocation takes effect at the next review attempt; no further reads occur.

Retention

Review findings are retained for 30 days after the review completes and are then deleted, unless your provider pins the review as a comparison baseline, in which case it is retained until unpinned. Records that consent was granted, that this addendum was accepted, that a review ran and that consent was revoked are kept permanently in an append-only log that no one, including SCOUTz, can alter or delete. They record the acting identity, email address and source IP address, the action and its outcome. They contain no tenant data and no findings. The record that your data was read outlives the data itself, by design.

Data processing

Your provider is the controller of the review; SCOUTz processes the data on your provider's instructions under the SCOUTz Data Processing Addendum, version 2026-06-oauth-readonly-v1, which is accepted on the consent page before you are sent to Microsoft.

Where data is processed

In the United States, on infrastructure operated by Railway Corporation.

Sub-processors

Microsoft Corporation (Microsoft Graph API, the source of tenant data). Railway Corporation (hosting). The following services are used only by the domain review and receive a domain name or a public IP address, never tenant configuration data: Shodan, Have I Been Pwned, Spamhaus, FIRST (EPSS), CISA (Known Exploited Vulnerabilities catalogue), Apollo.io (company enrichment), Brave Search, Google Safe Browsing, Sectigo crt.sh (certificate transparency), and RDAP registries.

No warranty of completeness

A review reports only what it could read. Where a permission, licence or service prevented a read, the report says so and does not treat it as a clean result.

Changes

SCOUTz will not add a permission to the application without publishing an updated permission list at these URLs and requiring a new consent.

Governing law

These terms are governed by the laws of the State of Arizona. Disputes are heard in the state or federal courts located in Arizona.

Contact

privacy@scoutzsecurity.io for privacy requests and support. Postal: SCOUTz LLC, c/o Republic Registered Agent LLC, 3101 N. Central Ave, Ste 183, Phoenix, AZ 85012.