Security reviews start with one question: does the platform hold our personal data? It does, and this page says exactly which fields, why each one is needed, how long it is kept, and what you can switch off.
Last reviewed: August 31, 2026
Unsave is an identity and posture product. A finding like “this account holds Owner at subscription scope” is worthless without the name of the account, so we store display names, user principal names and object IDs for the principals that appear in your Azure, Entra, Windows 365 and GitHub estate. We do not store what those people produce.
Never read, never stored
Stored, per the map below
This is the complete set of personal fields the platform persists. Anything not listed is either derived state, resource configuration with no person attached, or not collected.
| Source | Personal fields stored | Why it is needed | Retention |
|---|---|---|---|
| Your Unsave sign-in | name, email, alternate emails, Entra object ID, last login | Authentication, matching invites across UPN and mail aliases, and role assignment inside your organization. | Life of account |
| Azure RBAC | principal ID, display name, principal type, scope, role | Naming who holds privileged roles. A finding that says an unnamed object holds Owner cannot be acted on. | Your policy |
| Entra directory | group ID, group name, member lists, effective access paths | Resolving inherited access. Group nesting is where standing privilege usually hides. | Your policy |
| Windows 365 | user principal name, display name, device name, last login result | Attributing a Cloud PC to its assigned user for provisioning, grace period and licence waste views. | Your policy |
| App registrations | owner IDs, credential expiry dates, assigned permissions | Expiring secret alerts, routed to the person who owns the registration. | Your policy |
| GitHub EnterpriseOptional | login, name, verified emails, SAML name ID, SSH and GPG fingerprints, credential authorizations | Seat waste, two-factor coverage, and which credentials are SSO authorized against your orgs. | Your policy |
| SharePoint sharingOptional | site name, site URL, sharing state | Copilot readiness. Finds anonymous and org-wide links before Copilot surfaces them. No file contents, no file names. | Your policy |
| Platform activity | actor ID, action, target, timestamp, IP | Your audit trail of what was viewed and changed inside Unsave. | 90 days |
| Administrator actions | actor ID, action, target, timestamp | A separate, longer trail covering support and platform administrator access. | 365 days |
Access
The core connection consents to read scopes only, such as Directory.Read.All and the Azure Reader role. The only write permissions in the product belong to the optional Cloud PC operations module and require their own separate consent.
Access
Scopes are grouped by module. Declining Copilot readiness or Cloud PC operations means those permissions are never requested, and the rest of the platform reports as healthy rather than broken.
Collection
Collectors request a named list of fields from Microsoft Graph rather than whole objects. The Cloud PC collector, for example, selects 24 named fields. A property we do not ask for never reaches our network.
Storage
Account data and tenant metadata live in Azure Canada Central: PostgreSQL flexible server, container apps, and a Key Vault scoped to each environment.
Storage
Encrypted at rest by the platform, and TLS 1.2 or higher in transit with HSTS enforced. Connection secrets and integration tokens carry a second layer: AES-256-GCM with a unique initialization vector per value, keyed from Key Vault.
Isolation
Every stored row carries its organization, customer and tenant ID, and every query is scoped through them. Inside your organization, role-based access applies, plus a separate per-user gate on the GitHub section.
Lifecycle
Your organization carries a retention window. A nightly job deletes history past it across posture, compliance, cost, scan and Cloud PC tables, backed by scheduled database jobs that hold fixed ceilings on logs regardless of configuration.
Lifecycle
Consent is yours. Removing the enterprise application in your tenant severs collection immediately. There is no agent to uninstall and no inbound network path into your estate.
Stated as current limitations, not roadmap.
One subscription, a 30 day retention window, and every optional module off. Run it for two weeks, ask us at any point in that window for an export of what we hold, and widen the scope only once your team is satisfied with what the data map turned out to contain.
Questions from a security or privacy review go to privacy@unsave.io. See also our Privacy Policy and Terms of Service.