Last updated: July 18, 2026
This Privacy Policy explains how Soviron LLC ("Soviron," "we," "us") collects, uses, and protects information in connection with the Soviron security posture monitoring service (the "Service"). Soviron is a United States company. Our primary application infrastructure and database are hosted in the United States; some service providers may process information in other locations, as described below.
This policy applies to:
Soviron handles information in two distinct roles:
Account information. When you create an account or request access, we collect your name, email address, company name, and anything you choose to provide. For team accounts, we store the names, email addresses, and roles of invited users. Passwords are stored only as salted hashes, never in readable form.
Domain and web monitoring data. For the domains you connect, we read and retain posture and availability information: SSL certificate details, uptime and response status, DNS and MX records, email-authentication records (SPF, DKIM, DMARC), and domain-registration expiry and status. For WHOIS / registration monitoring we retain expiry and status metadata only; we do not store full registrant contact records.
Microsoft 365 / Microsoft Entra data. Under read-only permissions a Customer's administrator explicitly consents to, and only for the checks the Customer enables, the Service may access and retain: tenant and connection identifiers; user display names and user principal names (email addresses); whether individual users are licensed; individual multi-factor authentication registration and coverage status; the names and members of privileged administrator roles, and additions to or removals from those roles; license assignment and usage information; and connection-health and polling results. From this source data the Service generates its own internal findings, history, status, suppression ("accepted as intentional") decisions, audit entries, alerts, and reports. We do not modify, write to, or take administrative action in any connected environment; access is strictly read-only.
Billing information. When you subscribe, payment is processed by Stripe, which collects your payment-card details directly under its own terms. Soviron does not receive or store full card numbers. We retain billing records such as your subscription status, plan, monitored-client and connected-tenant counts, invoices, and the card brand and last four digits as returned by Stripe.
Support communications. If you contact us, we keep the content of your message and our response, including support cases, threaded replies, and any files you attach.
Technical and usage data. We collect standard technical information needed to operate and secure the Service, such as log data, IP addresses, timestamps, and error diagnostics.
Cookies. We use strictly necessary cookies to keep you signed in and secure your session. Our website uses Cloudflare Turnstile for bot protection on forms, which may set Cloudflare cookies. We do not use advertising cookies or sell information collected through cookies.
We obtain information from: you and your invited users; customer-authorized Microsoft Graph access; public DNS, certificate, domain-registration, and website endpoints for the domains you monitor; Stripe (billing status); customer-connected Slack and Teams destinations; your support messages and attachments; and automatically generated server, application, scheduler, and security logs.
We use the information we collect to: provide, operate, and maintain the Service, including running monitoring checks and sending alerts; authenticate users and secure accounts; notify you of findings, status changes, and service matters; process payments, manage subscriptions, and prevent billing abuse; respond to your requests and provide support; improve the reliability and security of the Service; and comply with legal obligations.
When the Service detects a finding, it may notify the recipients and channels a Customer has configured. This can include email (sent through our email provider) and, where a Customer connects them, Slack or Microsoft Teams. Some findings are shown only in the dashboard and are not sent as alerts. Alert content is limited to the monitoring information needed to describe the finding.
We share information only as needed to run the Service and as required by law. Specifically, we may disclose information: at your direction, or to the account users and alert recipients you configure; to the service providers listed below, acting on our behalf; to comply with a subpoena, court order, or applicable law; to investigate or address fraud, abuse, or security incidents, and to protect Soviron, our customers, or others; in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to this policy; and to professional advisers under confidentiality obligations.
We use a small number of providers to operate the Service, grouped by function. Each processes data only as needed for its function. The current, maintained list is published at our Subprocessor List; the summary below is provided for convenience.
| Function | Provider | Role |
|---|---|---|
| Application, scheduler, and database hosting | The Constant Company (Vultr) | US infrastructure |
| Encrypted off-site database backups | Backblaze | Backup storage |
| Uptime and backup liveness monitoring | Healthchecks.io | Operational monitoring |
| Payment processing and subscription billing | Stripe | Payments |
| Transactional and alert email delivery | Resend | Communications |
| Support mailbox (support@soviron.com) | Microsoft 365 / Exchange Online | Communications |
| Bot protection (Turnstile) and web security | Cloudflare | Web security |
| Read-only access to customer-authorized M365 data | Microsoft (Graph API) | Customer-directed source |
| Alert delivery to a connected Slack workspace | Slack | Customer-directed destination |
| Alert delivery to a connected Teams channel | Microsoft Teams | Customer-directed destination |
Customer-directed sources and destinations (Microsoft Graph, Slack, Teams) operate only because a Customer chooses to connect them. We post material changes to our subprocessors on the Subprocessor List; please check that page for the current list.
Soviron's primary application infrastructure and database are hosted in the United States, with encrypted backups stored off-site. Some providers above (for example, Stripe, Microsoft, Cloudflare, Resend, Slack) are global and may process certain information outside the United States, including where a Customer directs data to a destination in another region.
We keep information for as long as needed to provide the Service and meet legal obligations. Specific periods:
We take security seriously, as it is the purpose of our product. Measures include strictly read-only, least-privilege access to monitored Microsoft 365 environments, limited to the permissions required for the checks you enable; passwords stored only as salted hashes; authentication credentials and access tokens protected using access controls and secure server-side storage appropriate to their type, with measures to keep them out of application logs; encrypted transport (TLS); encrypted off-site backups; access controls and account isolation; and United States-based hosting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify affected customers and, where required, regulators, in accordance with applicable law.
You may access or update your account information, request deletion of your data, or disconnect a monitored environment at any time. Where we process data on behalf of a Customer (for example, an MSP's End Client data), please direct requests to the Customer that connected the environment or the relevant End Client, as applicable, and we will assist them as described in our DPA. Depending on where you live, you may have additional rights under applicable law, including to access, correct, or delete personal information. We will not discriminate against you for exercising these rights. To make a request, contact privacy@soviron.com.
We do not sell or share personal information as those terms are defined under California law, and we do not use it for cross-context behavioral advertising. We do not use advertising cookies or collect information about your activity across unaffiliated websites for targeted advertising; because we do not engage in that type of cross-site tracking, browser "Do Not Track" signals do not change how the Service operates. California residents may request to know, correct, or delete personal information by contacting privacy@soviron.com. Depending on our size and activities, some California privacy laws may not apply to us as a covered business; regardless, we will honor reasonable access, correction, and deletion requests.
The Service is intended for business customers in the United States and is hosted in the United States. If you access the Service from outside the United States, you understand your information will be processed in the United States and in the provider locations described above.
The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children.
We may update this policy from time to time. We will post the updated version with a revised "Last updated" date and, where appropriate, notify customers of material changes.
Questions about this policy or your data can be directed to privacy@soviron.com.