Securenix · Technix IT AB Data processing annexThe technical annex to the data processing agreement: every source Securenix reads, every permission the customer's Global Administrator consents to, what Securenix keeps of it and for how long. It describes the product as built, not as planned. Data controller The customer, for everything Securenix reads in their Microsoft 365 tenant and their on-premises environment. Data processor Technix IT AB, org. no. 559237-0711. Hosting swedencentral Microsoft Azure. App Service, Azure SQL and Key Vault all run in the same region; nothing is copied to another region. Direction Read-only Securenix holds read permissions only and never writes anything in a customer tenant. A write permission would be a new consent, not a new setting. § 1
SourcesSecurenix reads from four places and nowhere else. Two carry personal data about the customer's people, one carries none, and the fourth is Technix's own staff.
There is no schedule: a scan runs when a technician starts one, and an on-premises audit exists only if someone ran the collector. Nothing is polled in the background. § 2
Permissions the customer consents toApplication permissions RoleManagement.Read.DirectoryDirectory.Read.AllOrganization.Read.AllSecurityEvents.Read.AllPolicy.Read.AllAuditLog.Read.AllDomain.Read.AllDeviceManagementConfiguration.Read.AllDeviceManagementManagedDevices.Read.AllUser.Read.AllSharePointTenantSettings.Read.All
The consent link asks for .default, which grants exactly the permissions configured on the app registration — Securenix can never name a scope the registration does not already hold. The list at the moment of consent is stored on the consent record, so it is known who has to consent again if it changes. Every permission is a read permission. There is no write scope, and adding one would mean a new consent for every customer rather than a configuration change. Each check declares the permissions it needs, and the list above is exactly their union. Not read No mailbox, file, SharePoint, OneDrive, Teams or calendar content. No password hashes and no secrets. Sign-in logs are read only for the legacy-authentication check, over the last 30 days, and only the client app and the account are kept. § 3
What each control area readsEvery check asks Graph for named properties with $select, follows paging, and stores as evidence only what the finding has to show. Names and addresses from Graph are always rendered as plain text, in the app and in the report.
The partner-relationship area of the specification is not built: the GDAP API can only be read from the partner's own tenant, so Securenix's app-only token in the customer tenant is on the wrong side of that interface. No permission is requested for it. § 4
DNS lookupsSPF, DKIM and DMARC are public DNS records and need no tenant permission. Lookups run server-side and only for domains on the customer's stored list: the tenant's verified domains from Graph plus any domain a technician added on the customer page, validated on the way in. A host name never travels from a request into the resolver. TXT <domain> · TXT _dmarc.<domain> · CNAME/TXT selector1._domainkey.<domain> · CNAME/TXT selector2._domainkey.<domain> The records themselves are public policy data and contain no personal data. Results are not cached between scans. § 5
On-premises collectorOptional, and used only where the customer has an on-premises environment and agrees to it. A technician downloads a per-customer PowerShell script, runs it inside the customer's network, and it uploads one JSON document over HTTPS with an expiring, revocable token bound to that single customer. Securenix never connects to the customer's network itself. Active Directory Password policy, privileged group membership, stale and disabled accounts, accounts with non-expiring or old passwords, trusts, LAPS, domain controller and hybrid configuration. Account names and group memberships are personal data. Servers Operating system and patch level, firewall, SMB and NTLM configuration, TLS, RDP, endpoint protection, backup, BitLocker, event logging and local administrators. Server names and local account names are included. The uploaded document is kept verbatim as evidence, together with the findings derived from it, and is covered by the customer deletion. The upload is treated as untrusted data and is only ever rendered as plain text. § 6
Technix staff sign-inSign-in is Entra ID against the Technix tenant, and access requires membership in one Entra security group. These claims are read from the id token: oid, preferred_username, name They live in the session cookie for the length of the session. The user principal name is stamped on audit rows and on the scans and links the technician creates. There is no separate sign-in table, and no IP address or user agent is stored. § 7
What Securenix generatesBeyond what it reads, Securenix stores records of its own. All of them except the audit log are owned by one customer and are erased with that customer.
Credentials and secretsThe scanning app authenticates with a certificate from Key Vault in Azure, reached with a managed identity. Access tokens are never stored: they live in memory keyed by tenant id for the length of a run. The database uses Entra-only authentication, so no connection string holds a password. No secret, token or certificate is ever written to a log. § 8
Isolation and retention
§ 9
Special categoriesSecurenix processes no special categories of personal data under Article 9, and no personal identity numbers. Nothing it reads is content: names, addresses and device names appear only as identifiers of the accounts and machines whose security configuration is being assessed. ContactQuestions about this annex, or about a source you do not recognise here, go to Technix at the address below. This annex describes Securenix as built. The permission list is the one the application is configured with; endpoints and stored fields mirror the checks in the code. If they diverge, the code is what runs and this page is wrong — tell us. Last updated 2026-09-10. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||