How We Connect

Your data, your control.
Every detail, right here.

This page is for your security team, your compliance officer, or any examiner who wants to verify exactly what sEyeber Hub reads from your Microsoft environment, how it is protected, what is stored, and how you take it all back. No jargon. No surprises.

23 read-only permissions Zero write access Revoke anytime — no call needed
No email or mailbox content
No file or document contents
No Teams or chat messages
No passwords or secrets
No write, send, or delete permissions
What We Read

Six categories — all read-only, all optional except one.

sEyeber Hub reads your Microsoft security configuration across six plain-language categories. Your Microsoft Global Administrator approves access before any scan begins. All six are on by default; you can turn off any of the optional five before approving. The first category — confirming which organization we're connected to — is required and cannot be turned off.

Your organization & who has admin rights

We confirm which organization we're connected to, which Microsoft licenses are active, and who holds administrator roles — including whether those accounts are permanently assigned or only activated when needed.

"Two users hold standing Global Admin rights with no time limit."
Your users & how they sign in

We read user accounts, which second-factor methods each person uses (type only — never the phone number or code behind it), and any accounts Microsoft has flagged as risky. We read method types, never credentials.

"Eight users rely on text-message codes only. One account has been unused for 67 days."
Third-party & AI apps connected to your tenant

We read which third-party applications your users have connected to Microsoft 365 and what each one is permitted to access. This is where unauthorized AI tools typically appear.

"A widely-used AI tool was connected by 14 users and is not listed in your AI Use Policy."
Your sign-in & access policies

We read your Conditional Access rules — who can sign in, from where, and under what conditions. These policies are the front line of access control and the place where small gaps become large exposures.

"Legacy sign-in that bypasses multi-factor authentication is still permitted for 12 users."
Your managed devices

We read your device inventory — which laptops and phones are enrolled, whether they're encrypted and compliant, and which apps are deployed to them. We read compliance state, not device contents.

"Three laptops are missing disk encryption. One hasn't checked in for 41 days."
Security alerts & your Microsoft Secure Score

We read what Microsoft already flags — active alerts, incidents, your Secure Score trend, sensitivity label coverage, and which SharePoint sites are configured for broad sharing. We read site inventory, never document contents.

"Your Secure Score dropped 11 points. 17 SharePoint sites are missing sensitivity labels."
Your Data's Journey

What happens between Microsoft and your report.

From the moment data leaves your Microsoft environment, it is protected at every step before it reaches your report. Here is exactly what happens.

Your Microsoft 365
Read-only. Nothing written back.
Encrypted in transit
TLS protects every byte as it travels.
TLS
Sanitized
Sensitive details stripped before storage. Verified by automated tests on every release.
Encrypted at rest
AES-256. Keys held separately in Azure Key Vault — a breach of our systems alone reveals nothing.
AES-256 · Azure Key Vault
Your report
NIST CSF 2.0 findings. Yours only.
What We Store & For How Long

Your data, kept only as long as it serves you.

sEyeber Hub stores only what is needed to deliver your reports, findings, and compliance record. We do not retain raw evidence indefinitely. Here is exactly what is kept, and for how long.

Retention schedule
How long we keep different types of data
Raw technical evidence 30 days (default)
Your findings & scores Duration of subscription
Compliance history & documentation 5–10 years (configurable)
Minimum retention floor 5 years (SEC Rule 204-2)
How your data is kept
Private, isolated, and encrypted

Your data lives in your own private, encrypted vault — entirely separate from every other firm. Your scan data is not pooled, not shared, and not accessible to any other customer of sEyeber Hub.

Your encryption keys are held in Microsoft Azure Key Vault — a Microsoft-managed service outside our application layer. A breach of sEyeber Hub's systems alone cannot decrypt your stored data.

AI & Your Data

AI that works for you — and only you.

sEyeber Hub uses AI to generate findings, narrative summaries, and recommended next steps. Every AI operation is scoped to your organization only.

Your scan data is never used to train shared AI models. It does not become context for another firm's analysis. It does not leave your organizational boundary during AI processing.

This design follows the NIST AI Risk Management Framework — the federal standard for responsible AI governance — which is built into our product architecture, not layered on afterward.

AI processing is scoped to your organization — your data does not enter another firm's AI context
Your scan data is not used to train any shared model without your explicit opt-in
AI generates findings and recommendations — it does not take action in your environment
AI access to your data is governed by the NIST AI RMF — the same framework regulators reference
You're in Control

Disconnect anytime. No call. No ticket. No waiting.

You do not need sEyeber Hub's involvement to revoke our access. Two paths, both immediate, both entirely in your hands.

1
Inside sEyeber Hub

Go to Settings → Microsoft Connection → Disconnect. Access is revoked immediately. New scans stop at once.

2
Directly in your Microsoft admin center

Remove the sEyeber Hub enterprise application from your Microsoft Entra admin center. This works completely independently of us — you do not need to log into sEyeber Hub at all.

After you disconnect: Your existing findings, scores, and compliance history remain available to export. Your data is retained per the schedule above, then removed — nothing is deleted without your instruction. You can download a full export of your findings and evidence at any time.

Ready to see what's in your environment?

Read-only. Encrypted. In your hands from day one. No surprises — just the facts your firm needs to stay ahead of the next exam.

Questions? Email security@seyeberhub.com — our team reviews every message.

Diligence questions

What security and compliance teams ask us most

For the full list, see the FAQ. For the emotional trust overview, see Trust & Security.

Who has to approve the Microsoft connection?

A Microsoft Global Administrator or Privileged Role Administrator must approve the connection on behalf of your organization. Microsoft shows its own approval screen listing every permission before your admin approves. sEyeber Hub cannot bypass or pre-approve this step.

Can we approve only some of the six categories and not others?

Yes. Before your admin approves, each of the five optional categories can be individually turned off. The first category — confirming your organization identity and license state — is required and cannot be turned off, because it is how we verify which organization we are connected to. Any category you exclude will be marked "Excluded by you" in your report rather than silently omitted.

Does sEyeber Hub have access to SharePoint files?

The Microsoft permission we use for SharePoint is technically capable of reading file contents — but sEyeber Hub does not use that capability. We read only your site inventory and sharing settings (which sites exist, how they are configured for sharing). We do not read, access, or store the contents of any SharePoint document. This is enforced by our field allow-list and verified by automated tests on every release.

What happens to our data if we cancel our subscription?

Your findings, scores, and compliance documentation are available to export at any time. After cancellation, your data is retained per the applicable retention schedule (minimum 5 years to meet SEC Rule 204-2), then removed. Nothing is deleted ahead of schedule without your explicit instruction.