Plain language about what we see, where it lives, and what we never touch.
SimpleEntra is a read-only security posture tool. We have made this page straightforward for CISOs, DPOs and auditors to get an overview. For more technical depth — see our technical walkthrough.
SimpleEntra is provided by Zaulich ApS (company registration details provided to contracting parties as part of the Data Processing Agreement). Under GDPR we are a data processor — your organisation (or your MSP) is the data controller. We only process data on instruction from the data controller, documented in the Data Processing Agreement.
We read Microsoft Graph data from your Entra ID tenant via a set of read-only Application permissions. Specifically:
We never read email, calendars, OneDrive files, SharePoint content, Teams messages or any user-generated content. Mail.Send, Mail.Read or similar do not exist in our permission set.
We process personal data on the basis of the Data Processing Agreement with you (data controller), pursuant to art. 28 GDPR. The data controller decides purpose and means. SimpleEntra's purpose is limited to:
All persisted data is stored in Supabase Postgres in AWS eu-central-1 (Frankfurt). We store all your data in the EU. Supabase is certified under SOC 2 Type II and HIPAA.
Connections between all components (customer browser → portal → database) are TLS 1.2+. Data at rest is encrypted by Supabase (AES-256 via AWS KMS). Graph tokens are not stored permanently — they are fetched fresh on each call via client credentials flow.
Data is retained while you're an active customer. On cancellation we delete everything within 30 days — findings, sign-ins, devices, users. If you revoke consent, contact us for immediate deletion.
If you delete your tenant from the portal, we delete all associated data immediately. If you revoke admin consent in Microsoft Entra, our next Graph call will fail and our scans will stop. Contact us if you want the historical data deleted right away.
We use the following third-party processors. The list is exhaustive — there are no others.
| Provider | Purpose |
|---|---|
| Supabase | Postgres database + authentication · Region: EU-Frankfurt · Scope: all persisted customer data · DPA via Supabase |
| Microsoft Graph | Read-only data collection from your tenant's region · Transient — data processed in transit |
| Vercel | Hosting of portal frontend · Region: Frankfurt (fra1) · Processes no customer data persistently — request/response stream only |
We map every check to publicly available standards — CIS Microsoft 365 Benchmarks, CISA SCuBA and EIDSCA. We do not invent our own controls. The test catalog itself is developed and maintained by the SimpleEntra team based on real-world experience with Entra ID configurations.
No affiliation: SimpleEntra is not affiliated with, endorsed by or sponsored by Microsoft unless explicitly stated.
A signed Data Processing Agreement is a mandatory prerequisite for production use. Contact us for a copy.
Read the current draft (GDPR Art. 28 — final document reviewed by legal counsel before signing): SimpleEntra-DPA-en.pdf.
As a data subject you have the right to:
Requests about these rights are handled primarily by the data controller (your MSP or organisation). For technical questions about what data SimpleEntra holds, contact us directly — see below.
We use no tracking cookies on simpleentra.com. No Google Analytics, no Meta Pixel, no advertising trackers. If we add analytics later, we will use a privacy-first solution (Plausible or similar) and update this page.
The demo at /demo (proxied from our portal) sets one technical cookie (simpleentra_demo) to give you access to the demo tenant. It expires after 4 hours.
If we discover a personal data breach involving your data, we will notify the data controller without undue delay — at the latest within 72 hours of becoming aware (the GDPR standard). The notification will include the nature of the breach, categories and approximate number of affected individuals, consequences, and remedial measures.
Questions about data handling, DPA, deletion or rights:
Mads Zaulich
Zaulich ApS
hello@simpleentra.com
Complaints can also be submitted to the Danish Data Protection Authority (datatilsynet.dk).