Privacy & Data Handling
Last updated: July 2026
Who we are
LockList Security LLC, a Montana limited liability company ("LockList", "we", "us"), provides on demand Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne security and compliance assessments. This page explains exactly what data is and isn't handled when you use the assessment at locklistsecurity.com/scan.
How the assessment works
You sign in with your own Microsoft 365, Google Workspace, GitHub, AWS, or Azure account using the provider's standard sign in (OAuth). The access token issued by the provider stays in your browser's local storage. It is never transmitted to or stored by us. The assessment then reads your configuration by calling the provider's API (Microsoft Graph, the Google Workspace Admin SDK, the GitHub API, or the AWS and Azure management APIs) directly from your browser. That configuration data is evaluated locally in the page; it is not sent to our servers during the scan.
NinjaOne works slightly differently: you supply your own read only NinjaOne API client credentials (Monitoring scope), and because NinjaOne's API does not accept direct browser calls, requests are relayed through a stateless LockList Worker that forwards them to your regional NinjaOne instance and returns the response. The relay only accepts a fixed allowlist of read only endpoints, and your credentials, tokens, and results are never stored or logged — they pass through in memory only. Results are still evaluated in your browser.
Google Workspace data we access
When you run a Google Workspace assessment, LockList requests the following read only Google OAuth scopes and uses the data solely to compute your security findings, in your browser:
- openid, email, profile — the signed in administrator's identity (name, email address, profile picture) to display who is signed in.
- admin.directory.user.readonly — the account list to evaluate 2‑Step Verification coverage, admin protection, super‑administrator count, and suspended/dormant accounts. Fields read: primary email, admin and delegated‑admin flags, 2SV enrollment/enforcement status, suspended status, and last login time.
- admin.directory.rolemanagement.readonly — administrator role assignments, to review privileged access.
- admin.directory.domain.readonly — your domains and their verification status.
- admin.directory.customer.readonly — basic account information (customer ID, primary domain, organization name) to label your report.
- admin.reports.audit.readonly — a small sample of recent login and admin audit activity, only to confirm that audit logging is accessible.
We request the minimum scopes needed for these checks, and all of them are read only. LockList makes no changes to your Google Workspace environment.
Microsoft, GitHub, AWS, Azure & NinjaOne permissions
- Assessment (read only): delegated read permissions used only to read your current settings (e.g. Directory.Read.All, Policy.Read.All, AuditLog.Read.All for Microsoft; organization read for GitHub; the SecurityAudit IAM role for AWS; the Reader role for Azure; and a customer created API client with the Monitoring scope for NinjaOne).
- Fixes (optional, write — Microsoft only): if you choose to apply a remediation, we request the specific write permission for that fix at that moment. Conditional Access fixes are created in report only mode and only enforced as a separate, explicit action you take. We never change your tenant without your click. Google Workspace is read only; we do not request any Google write scopes.
With whom we share your data
We do not sell, rent, or share your Google Workspace data — or any other provider's data — with third parties for their own purposes, advertising, or any secondary use. We use a small number of infrastructure providers ("subprocessors") strictly to operate the service:
- Cloudflare hosts the website and runs the minimal server function (a Cloudflare Worker) that generates your report file or signed trust badge at the moment you click download. To produce that file, your assessment results — which can include limited Google‑derived data such as administrator email addresses shown as evidence — are transmitted to the Worker over an encrypted connection, used in memory to render the file, and then discarded. They are not written to any database, and are not logged or retained. The same Worker relays read only NinjaOne API requests (NinjaOne's API does not accept direct browser calls); relayed credentials, tokens, and responses pass through in memory and are likewise never stored.
- Stripe processes payments. Stripe never receives any Google Workspace data or assessment results; it handles only your payment details, which you enter directly into Stripe's secure fields.
We disclose data only if required by law (for example, a valid legal request), and we operate no database of customer assessments. There are no user accounts.
AI / machine learning
LockList does not use artificial intelligence or machine learning to perform your assessment. Every security check is deterministic, rule‑based logic that runs in your browser, and reports are generated by fixed templates. LockList does not send your data to any AI system.
We do not transfer any Google user data to third‑party AI/ML services, and we do not use raw, aggregated, anonymized, or derived Google Workspace data to develop, train, or improve any generalized or foundational AI/ML model.
How we protect your data
- All connections use encryption in transit (HTTPS / TLS).
- Your OAuth access token stays in your browser's local storage and is never transmitted to or stored by us.
- Google Workspace configuration is read and evaluated locally in your browser; it is not sent to our servers during the scan.
- The only server processing — report and trust‑badge generation — is ephemeral and in memory; results are discarded immediately after the file is produced, never persisted or logged.
- We keep no database of assessments and no user accounts, so there is no stored trove of customer data to breach.
- We request the minimum, read‑only scopes needed, and report downloads are gated by short‑lived, cryptographically signed tokens.
Data retention
Assessment results live only in your browser tab for the duration of your session. Closing or refreshing the page clears them. We keep no copy. Data transmitted transiently to generate a report or trust badge is discarded as soon as the file is produced.
Cookies & tracking
We do not use advertising or third party tracking cookies. The sign in library stores authentication state in your browser's local storage so you don't have to sign in repeatedly; clearing your browser storage removes it.
Your control
You can revoke LockList's access at any time from your Google Account's third‑party access settings, or from your Microsoft account at myapps.microsoft.com.
Contact
Questions about privacy or security? Email admin@locklistsecurity.com.