Trust & security

How SYAGA Audit protects your tenant, step by step.

SYAGA Audit audits your Microsoft 365 security configuration without ever touching it, with no server agent and no access to your content. Here's exactly how.

We only read No writes

SYAGA Audit only read your tenant's configuration: the audit is 99% read-only. An add-on (SharePoint all sites, Defender) that Microsoft does not allow to be reached through any read access: the narrowest it offers is write-capable. This is not our limit, it is that of the Microsoft API. We offer it to you as an option, justified, and you decide. In all cases we never write anything: the operation takes place on your side, never on our servers, and you verify it yourself on the consent screen and in your own Microsoft logs.

  • We only read - we never write anything to your tenant.
  • No access to your emails, files or content - only the security settings.
  • Your settings, accounts and data remain untouched.

Explicit, revocable consent Microsoft OAuth

Access is granted by your administrator via the consent screen official Microsoft, which lists the requested permissions. You remain in control at all times.

  • No password is ever shared with us (Microsoft OAuth).
  • The consent screen shows precisely which permissions are granted.
  • Revocable in one click at any time from Entra ID (Azure AD).

No agent, no server-side agent No software

SYAGA Audit works entirely remotely, via the Microsoft API. Nothing to deploy on your side, no added attack surface on your network.

  • No software or agent to install.
  • No PowerShell script to run on the client side.
  • No inbound connection to your network.

Sovereignty Hosting in Europe

The SYAGA Audit infrastructure is hosted in Europe. Your audit results remain subject to French and European law.

  • Hosting in Europe, French and European law applicable.
  • Compliant with the European GDPR framework.
  • A sovereignty-oriented approach (NIS2, ANSSI).

Transparency Traceability

Every audit is timestamped and documented. An attestation and an integrity log (planned for launch) will accompany the report so that you can verify its provenance.

  • Time-stamped audit, with an associated attestation (planned at launch).
  • Audit integrity log (planned at launch).
  • You know what was read, and when.

Your data: what we keep (and what we don't do)

Let's be precise. Collection and pseudonymisation run in your browser (extension): your real raw data never leaves and is never sent to us. The service only receives pseudonymised fingerprints. Your audit results (score, gaps, tokenised report) are kept in your client area, for as long as you remain a client, so that you can reopen them and track your progress; they are re-contextualised in the clear only on your device. Your billing information (the strict legal minimum) are also retained, encrypted, never resold and deletable on simple request (GDPR).

  • Retained: only your billing information (client area, legal minimum).
  • Never resold, never transferred to third parties.
  • Raw tenant data: never transmitted (it stays in your browser). Audit results (score, gaps, report): kept tokenised in your client area, re-contextualised in clear form only on your side.
Ready to see clearly

Launch your least-privilege audit.

No installation, no password, revocable at any time.

A question about data protection? See the page Privacy.

The report is a diagnostic: it states what is observed, it does not fix anything on your behalf.