• Read-onlyWe request read-only access and cannot modify your environment.
  • EncryptedAny credentials you provide are encrypted at rest.
  • We never change your settingsEsmeris inventories and grades — remediation stays in your hands.

Read-only access

An Esmeris audit connects to your Google Workspace or Microsoft 365 tenant using a strictly read-only account. We can enumerate users, applications, tokens, and permissions — but we cannot change configuration, alter data, or act on behalf of your users. It is read-only by design, not by promise.

Before you connect anything, we provide documentation of the exact read-only scopes and roles we request, so your security team can review and verify them.

How credentials are handled

Where an audit requires stored credentials, they are protected with envelope encryption. Each credential is encrypted with AES-256-GCM — authenticated encryption with a unique key and a unique initialization vector per record — and that data key is itself encrypted by a hardware-backed key in AWS Key Management Service (KMS). Plaintext keys exist only momentarily in memory and are zeroed immediately after use, and credentials are never written to logs.

In practice that means a copy of the stored data is useless without access to our KMS key, and any tampering with the ciphertext is detected and rejected. Credentials are used only to perform the audit you requested.

What we access — and what we don't

We read configuration and access metadata: who has accounts, which third-party apps are connected, what scopes they hold, which admins have multi-factor enabled, and similar signals. We do not read the contents of your users' mailboxes, files, or messages, and we make no changes to your tenant.

Data handling & retention

Audit results are used to produce your graded report and are retained for 180 days by default. You can request deletion of your audit data at any time, and customers can configure a shorter or longer retention period to suit their own policies.

Who has access

Esmeris operates on a tightly limited-access model: audit data is accessible only to the operator running your audit. The internal audit tooling is not publicly exposed.

Contact-form & lead data

This website is operated separately from the audit tooling and never receives your tenant credentials. When you submit our contact form (the “Talk to us” page), we collect your name, work email, company, company size, platform(s), and any message — solely to respond to your enquiry. That information is stored on this site's infrastructure and is not connected to the internal audit system. Email notifications are sent via our email provider (Resend). See our Privacy Policy for details and your rights.

Reporting a vulnerability

If you believe you've found a security issue, please email security@esmeris.com, a monitored inbox. We welcome responsible disclosure and will respond promptly.