← Back to redpinecloud.com

Privacy Statement

Redpine Cloud Security LLC · Last updated September 11, 2026

Redpine Cloud Security LLC ("Redpine," "we," "us") provides Microsoft 365 and Microsoft Entra security assessments and related services to businesses. This statement explains what information we handle, why, how long we keep it, and what we will never do with it.

This statement covers two very different things, and we keep them separate on purpose:

  1. Visitors to redpinecloud.com, where we collect essentially nothing.
  2. Client environment data, which we access under a signed agreement to perform an assessment.

If you are a client, your signed agreement governs wherever it is more specific than this statement or conflicts with it.

1. Visitors to redpinecloud.com

We set no cookies. We run no analytics. We use no advertising or tracking pixels. There are no forms on the site.

That is unusual enough to be worth stating plainly. The site is a set of static pages. It does not profile you, does not follow you across other sites, and does not build a record of your visit.

Two things do happen, and you should know about them:

If you email info@redpinecloud.com or call us, we keep that correspondence so we can respond and maintain a record of our dealings with you.

We do not sell, rent, or share your contact information, and we do not add you to marketing lists you did not ask for.

2. Client environment data

This is the part that matters most, because a security assessment necessarily involves us looking at your systems.

What we access

With your written authorization, we access configuration and identity information in your Microsoft 365 and Microsoft Entra tenant. In practice this means things like: user and administrator accounts and their roles, multi-factor authentication and Conditional Access configuration, application registrations and consent grants, sharing settings, and mailbox rule configuration.

What we do not do

Changes to your tenant

If you engage us for remediation, that is separately authorized and separately scoped:

You can revoke our access at any time

You may withdraw either authorization at any time by written notice, and we will promptly stop using it. You can also confirm our access is gone yourself, in your own admin center.

3. Where your information is held

Assessment data, reports, and related working files are stored in Redpine's own Microsoft 365 tenant, hosted by Microsoft in the United States. Credentials used to reach client tenants are held in Azure Key Vault.

We use a small number of established providers to run the business. Where they touch information relating to you, it is limited to what that function requires:

ProviderWhat it is used for
MicrosoftTenant access, storage of assessment data and reports, email, scheduling
Anthropic (Claude)AI assistance with analysis and preparation of findings and documentation
CloudflareWebsite hosting and domain registration
Electronic signature providerSigning engagement agreements and acceptance forms
Accounting and invoicing providerInvoicing and payment records

Where a row names a function rather than a company, the specific provider is named in your engagement agreement, and we will tell you on request. We keep it that way because a public list of the exact products a security firm runs on is more useful to an attacker than it is to you.

A note on our use of AI

We think you should hear this from us rather than have to ask.

We use an AI assistant (Anthropic's Claude) as a working tool in performing analysis and preparing findings and documentation. In the course of that work it can process configuration data and findings from your tenant.

Our use is governed by Anthropic's commercial terms, which include a data processing agreement, and your data is not used to train AI models. Model training is additionally switched off on the account. It is a tool we work with, in the same way we work with Microsoft's platform. It does not make decisions about your security posture on its own, and a person reviews everything that reaches you.

We disclose this because "does any AI system touch our data" is a fair question that more buyers are asking, and a vendor who answers it only when pressed has told you something about how they handle the rest.

4. How long we keep it

Assessment engagements. Client data and the assessment report are retained for 30 days after delivery and then permanently deleted, except that we keep one archival copy of the final report for our records.

Redpine Watch (ongoing monitoring). Because detecting drift requires comparing against earlier scans, scan results and change reports are retained for the term of the agreement and for 12 months after it ends, then permanently deleted, again except one archival copy of the final report.

How we delete. When we say permanently deleted, we mean a deletion method that bypasses recoverable storage, rather than letting content quietly age out of a recycle bin. We want the retention period to be literally true.

One honest limitation. After deletion, residual copies may persist for a short period inside the underlying platform provider's own backup systems. That window is outside our control, and no provider can contract it away. We would rather tell you it exists than imply deletion is instantaneous everywhere.

Why we keep the final report. That single archival copy is our record of what we actually reported to you and when. If a question arises later about what we found or advised, it is the document that answers it. It is held under the same confidentiality obligations as everything else.

5. What we will never do

6. How we protect it

(Verified 2026-09-09 against Redpine’s own tenant: multi-factor authentication required for all users, legacy authentication blocked, BitLocker on. We hold ourselves to the controls we assess our clients against.)

If something goes wrong. If we become aware of a security incident affecting your information, we will notify you without undue delay and tell you what we know, what we are doing, and what we recommend you do.

(Deliberately not a fixed number of hours. Specific notification windows are agreed in individual client contracts where required, rather than promised publicly to everyone regardless of circumstance.)

7. Your choices

8. Business context

Redpine provides services to businesses. Our services are not directed to children, and we do not knowingly collect information from them.

9. Changes to this statement

If we change this statement, we will update the date at the top. Material changes affecting how we handle client data will also be communicated to affected clients directly rather than only posted here.

10. Contact

Redpine Cloud Security LLC 202 N Cedar Ave Ste 1, Owatonna, MN 55060 info@redpinecloud.com · 507-702-0002 · redpinecloud.com

© 2026 Redpine Cloud Security LLC. All rights reserved.