Privacy & Data Handling

Last updated: July 2026

The short version: Your Microsoft 365, Google Workspace, GitHub, AWS, Azure, or NinjaOne assessment runs entirely in your own browser. We request read only permissions for the assessment, we do not store your data or your sign in tokens, and we never use your data to train or improve any artificial intelligence or machine learning model.

Who we are

LockList Security LLC, a Montana limited liability company ("LockList", "we", "us"), provides on demand Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne security and compliance assessments. This page explains exactly what data is and isn't handled when you use the assessment at locklistsecurity.com/scan.

How the assessment works

You sign in with your own Microsoft 365, Google Workspace, GitHub, AWS, or Azure account using the provider's standard sign in (OAuth). The access token issued by the provider stays in your browser's local storage. It is never transmitted to or stored by us. The assessment then reads your configuration by calling the provider's API (Microsoft Graph, the Google Workspace Admin SDK, the GitHub API, or the AWS and Azure management APIs) directly from your browser. That configuration data is evaluated locally in the page; it is not sent to our servers during the scan.

NinjaOne works slightly differently: you supply your own read only NinjaOne API client credentials (Monitoring scope), and because NinjaOne's API does not accept direct browser calls, requests are relayed through a stateless LockList Worker that forwards them to your regional NinjaOne instance and returns the response. The relay only accepts a fixed allowlist of read only endpoints, and your credentials, tokens, and results are never stored or logged — they pass through in memory only. Results are still evaluated in your browser.

Google Workspace data we access

When you run a Google Workspace assessment, LockList requests the following read only Google OAuth scopes and uses the data solely to compute your security findings, in your browser:

We request the minimum scopes needed for these checks, and all of them are read only. LockList makes no changes to your Google Workspace environment.

Microsoft, GitHub, AWS, Azure & NinjaOne permissions

With whom we share your data

We do not sell, rent, or share your Google Workspace data — or any other provider's data — with third parties for their own purposes, advertising, or any secondary use. We use a small number of infrastructure providers ("subprocessors") strictly to operate the service:

We disclose data only if required by law (for example, a valid legal request), and we operate no database of customer assessments. There are no user accounts.

AI / machine learning

LockList does not use artificial intelligence or machine learning to perform your assessment. Every security check is deterministic, rule‑based logic that runs in your browser, and reports are generated by fixed templates. LockList does not send your data to any AI system.

We do not transfer any Google user data to third‑party AI/ML services, and we do not use raw, aggregated, anonymized, or derived Google Workspace data to develop, train, or improve any generalized or foundational AI/ML model.

Limited Use. LockList's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect your data

Data retention

Assessment results live only in your browser tab for the duration of your session. Closing or refreshing the page clears them. We keep no copy. Data transmitted transiently to generate a report or trust badge is discarded as soon as the file is produced.

Cookies & tracking

We do not use advertising or third party tracking cookies. The sign in library stores authentication state in your browser's local storage so you don't have to sign in repeatedly; clearing your browser storage removes it.

Your control

You can revoke LockList's access at any time from your Google Account's third‑party access settings, or from your Microsoft account at myapps.microsoft.com.

Contact

Questions about privacy or security? Email admin@locklistsecurity.com.