Privacy Statement
Redpine Cloud Security LLC · Last updated September 11, 2026
Redpine Cloud Security LLC ("Redpine," "we," "us") provides Microsoft 365 and Microsoft Entra security assessments and related services to businesses. This statement explains what information we handle, why, how long we keep it, and what we will never do with it.
This statement covers two very different things, and we keep them separate on purpose:
- Visitors to redpinecloud.com, where we collect essentially nothing.
- Client environment data, which we access under a signed agreement to perform an assessment.
If you are a client, your signed agreement governs wherever it is more specific than this statement or conflicts with it.
1. Visitors to redpinecloud.com
We set no cookies. We run no analytics. We use no advertising or tracking pixels. There are no forms on the site.
That is unusual enough to be worth stating plainly. The site is a set of static pages. It does not profile you, does not follow you across other sites, and does not build a record of your visit.
Two things do happen, and you should know about them:
- Hosting. The site is served by Cloudflare, which processes standard connection information such as your IP address in order to deliver pages and protect against abuse. This is Cloudflare acting as our hosting provider, under their terms.
- Scheduling. The "book a call" link takes you to Microsoft Bookings, a separate Microsoft service. If you book a meeting, you provide your name, email address, and chosen time directly to that service, and we receive it so we can meet with you. We use it to contact you about the meeting and the work you asked about. Nothing more.
If you email info@redpinecloud.com or call us, we keep that correspondence so we can respond and maintain a record of our dealings with you.
We do not sell, rent, or share your contact information, and we do not add you to marketing lists you did not ask for.
2. Client environment data
This is the part that matters most, because a security assessment necessarily involves us looking at your systems.
What we access
With your written authorization, we access configuration and identity information in your Microsoft 365 and Microsoft Entra tenant. In practice this means things like: user and administrator accounts and their roles, multi-factor authentication and Conditional Access configuration, application registrations and consent grants, sharing settings, and mailbox rule configuration.
What we do not do
- The assessment is read-only by construction, not merely by policy. It runs through a dedicated, least-privilege application registration that holds read permissions only. It is not technically capable of changing your tenant.
- We do not read the contents of your mail, files, or documents as part of the assessment. We look at how your tenant is configured, not at what your people wrote.
- We do not perform penetration testing, exploitation, password cracking, or social engineering.
Changes to your tenant
If you engage us for remediation, that is separately authorized and separately scoped:
- Write access is granted through a second, distinct application registration that you consent to independently. Redpine never holds standing write access to your tenant, even under a recurring agreement.
- Every change is previewed for you, with its prior state recorded, before it is applied.
- Every change is logged, and we retain the ability to reverse authorized changes for 30 days.
- When the agreed change window closes, our write access is revoked and we give you evidence of the revocation.
You can revoke our access at any time
You may withdraw either authorization at any time by written notice, and we will promptly stop using it. You can also confirm our access is gone yourself, in your own admin center.
3. Where your information is held
Assessment data, reports, and related working files are stored in Redpine's own Microsoft 365 tenant, hosted by Microsoft in the United States. Credentials used to reach client tenants are held in Azure Key Vault.
We use a small number of established providers to run the business. Where they touch information relating to you, it is limited to what that function requires:
| Provider | What it is used for |
|---|---|
| Microsoft | Tenant access, storage of assessment data and reports, email, scheduling |
| Anthropic (Claude) | AI assistance with analysis and preparation of findings and documentation |
| Cloudflare | Website hosting and domain registration |
| Electronic signature provider | Signing engagement agreements and acceptance forms |
| Accounting and invoicing provider | Invoicing and payment records |
Where a row names a function rather than a company, the specific provider is named in your engagement agreement, and we will tell you on request. We keep it that way because a public list of the exact products a security firm runs on is more useful to an attacker than it is to you.
A note on our use of AI
We think you should hear this from us rather than have to ask.
We use an AI assistant (Anthropic's Claude) as a working tool in performing analysis and preparing findings and documentation. In the course of that work it can process configuration data and findings from your tenant.
Our use is governed by Anthropic's commercial terms, which include a data processing agreement, and your data is not used to train AI models. Model training is additionally switched off on the account. It is a tool we work with, in the same way we work with Microsoft's platform. It does not make decisions about your security posture on its own, and a person reviews everything that reaches you.
We disclose this because "does any AI system touch our data" is a fair question that more buyers are asking, and a vendor who answers it only when pressed has told you something about how they handle the rest.
4. How long we keep it
Assessment engagements. Client data and the assessment report are retained for 30 days after delivery and then permanently deleted, except that we keep one archival copy of the final report for our records.
Redpine Watch (ongoing monitoring). Because detecting drift requires comparing against earlier scans, scan results and change reports are retained for the term of the agreement and for 12 months after it ends, then permanently deleted, again except one archival copy of the final report.
How we delete. When we say permanently deleted, we mean a deletion method that bypasses recoverable storage, rather than letting content quietly age out of a recycle bin. We want the retention period to be literally true.
One honest limitation. After deletion, residual copies may persist for a short period inside the underlying platform provider's own backup systems. That window is outside our control, and no provider can contract it away. We would rather tell you it exists than imply deletion is instantaneous everywhere.
Why we keep the final report. That single archival copy is our record of what we actually reported to you and when. If a question arises later about what we found or advised, it is the document that answers it. It is held under the same confidentiality obligations as everything else.
5. What we will never do
- We do not sell your data. Not to anyone, in any form.
- We do not share client data except as needed to perform the work you engaged us for, or where we are required to by law.
- We do not use your data for any purpose other than delivering the service you engaged us for. We do not mine it, repackage it, or use it to build products.
- We do not use client data to train machine learning models, and the providers we work with do not train on it either. See the note on our use of AI in Section 3.
6. How we protect it
- Access to client tenants is through least-privilege application registrations, scoped to the minimum permissions the work requires, and all access is logged.
- Read access and write access are separate applications, so read-only work cannot become a change by accident.
- Multi-factor authentication is enforced on all Redpine accounts, and legacy authentication protocols are blocked, both through Conditional Access policy.
- Data at rest in Microsoft 365 and Azure is encrypted by the platform, and endpoints used to perform the work use full-disk encryption.
- Client reports are held under a defined retention model rather than left indefinitely in general-purpose storage.
(Verified 2026-09-09 against Redpine’s own tenant: multi-factor authentication required for all users, legacy authentication blocked, BitLocker on. We hold ourselves to the controls we assess our clients against.)
If something goes wrong. If we become aware of a security incident affecting your information, we will notify you without undue delay and tell you what we know, what we are doing, and what we recommend you do.
(Deliberately not a fixed number of hours. Specific notification windows are agreed in individual client contracts where required, rather than promised publicly to everyone regardless of circumstance.)
7. Your choices
- Revoke our access to your tenant at any time by written notice.
- Ask what we hold about you or your organization, and we will tell you.
- Ask us to delete what we hold, subject to records we are required to keep, such as invoices and executed agreements.
- Stop hearing from us at any time by replying to any message or emailing the address below.
8. Business context
Redpine provides services to businesses. Our services are not directed to children, and we do not knowingly collect information from them.
9. Changes to this statement
If we change this statement, we will update the date at the top. Material changes affecting how we handle client data will also be communicated to affected clients directly rather than only posted here.
10. Contact
Redpine Cloud Security LLC 202 N Cedar Ave Ste 1, Owatonna, MN 55060 info@redpinecloud.com · 507-702-0002 · redpinecloud.com
© 2026 Redpine Cloud Security LLC. All rights reserved.