What we can see, and what we cannot touch
You are being asked to give a company visibility into an environment, and possibly into somebody else's. That deserves a page. Everything here is written so you can forward it without editing it.
Read only, consented, and revocable without asking us
Three of these are properties of how access is granted of the access grant itself, which matters, because a promise depends on us continuing to keep it.
ISO/IEC 27001 certified. Our information security management system is certified against the standard. Ask and we send the certificate and the scope statement so you can check exactly what it covers.
Consent goes through your provider
Authorisation runs through the provider's own consent process. We never ask for a password, we never see one, and we never store a credential. Nothing we hold can be used to sign in as one of your users.
Read only scope, no write permission at all
The application requests read permissions only. It has no ability to create, modify or delete anything. That is a property of the grant, so even a mistake on our side cannot change your environment.
Nothing is installed
No agent, no appliance, no script left scheduled. There is nothing to uninstall afterwards and nothing quietly running once the assessment finishes.
You can revoke it without contacting us
An administrator withdraws the consent directly, at any time. No email, no ticket, no waiting for a business day. Access is never tied to a commercial conversation.
We retain the findings and report
The platform reads configuration, licensing and billing information to produce findings. It does not read mail content, files, chat messages or documents, and the reports do not contain them.
What we retain is the findings and the report, because a scheduled assessment is worthless if it cannot compare against the previous one. Ask us to delete it and we will, and you get the record of that deletion.
Compliance findings are mapped to Essential Eight, NIST, CIS and ISO 27001. Every report states the version it was assessed against, because a maturity score without a version does not mean much. Older reports keep their original version.
The questions a client will put to you
Answers you can forward without rewriting them.
Can Optimizer365 change anything in our environment?
No. The grant is read only. There is no write permission to misuse and nothing installed that could act on its own.
Can Optimizer365 read our email or documents?
No. The assessment reads configuration, licensing and billing information. It does not request or receive mail, file or chat content.
How do we revoke access?
An administrator withdraws the application's consent. Access ends immediately and you do not need to tell us.
Are you certified?
Yes, ISO/IEC 27001. Ask and we send the certificate and the scope statement so you can check what it covers.
What happens to our data if we stop working with you?
Ask for deletion and we delete the findings and reports we hold, then confirm it. There is no retention period we hold you to.
Read the permissions before you decide
If something on the consent screen looks wrong for what we claim to do, that is a good reason to stop. Ask us and we will explain it.
Read only access. Nothing installed. You can stop at the report.