Security

Names and dates of credentials. Never the credentials.

GlacierPoint Remind knows what each item is, where it lives, who owns it and when it ends. It never holds a secret’s value or a private key, it holds no access to your tenant, and the work is done by an app on your computer, signed in as you.

Access

Who can touch the tenant.

Only people in your organization, with their own sign-in, and, for scheduled runs, an app registration your organization owns.

Read permissions only

A run asks Microsoft for read permissions and nothing else. The consent card in the app shows which were granted, and a missing optional one leaves its section out, said so on the report.

No vendor access

We hold no password, token, client secret or certificate for any tenant, and there is no support account or back door. Nobody at GlacierPoint can read or change your tenant.

Sign-ins stay with the app

You sign in to Microsoft in your browser. The sign-in is used by the app on your computer and never sent to the portal; a scheduled run asks for a fresh token every time and keeps none.

The one write, named honestly

Scheduled runs need an app registration of your own, “GlacierPoint Remind scheduled run”. The setup shows you every object before it is created, writes only to your directory, removes its own write permissions when it is done, and keeps a journal on your computer. Remove takes it all away.

Scheduled runs on your computer

A Windows task on a computer you choose, with a certificate made there whose private key Windows keeps and will not export. The schedule never lives at the portal, so the portal never holds a key to your tenant.

The portal never steers the app

What the app reads is fixed in the app. The portal receives runs; it cannot make the app read something else or run anything.

Your runs

Encrypted before they leave your computer.

What a run carries: names, dates, owners and states. What the portal does with it: the report and the warnings.

  • Sealed uploads. A run is compressed and encrypted on your computer with AES-256-GCM, under a key wrapped with the portal’s public key (RSA-OAEP), and bound to its tenant and run before it is uploaded.
  • Encrypted at rest. The portal stores every row encrypted under a data key kept outside the database, so a copy of the database alone reveals nothing.
  • Kept as long as your plan says. 30 days of history with the Preview and One-time, 400 days with Watch and MSP; closing a workspace deletes its tenants, runs and records.
  • Diagnostics without names. Error reports carry the status and the error code of Microsoft, never a token and never a user’s name.
Permissions

Every permission, by name.

Asked at sign-in, as delegated permissions; a scheduled run has the same seven as application permissions, and nothing that writes.

PermissionWhat it reads
Application.Read.AllThe secrets and certificates of app registrations and enterprise applications, by name and end date, and their owners
Directory.Read.AllOwners’ names and the state of directory synchronization
Domain.Read.AllYour domains, their verification and federation state
AuditLog.Read.AllThe last sign-in of each application, for the unused applications (optional)
DeviceManagementConfiguration.Read.AllThe Apple push certificate and the Apple tokens of Intune (optional)
DeviceManagementServiceConfig.Read.AllManaged Google Play and the certificate connectors of Intune (optional)
Policy.Read.AllConditional Access policies and the objects they name (optional)
Exchange Online, readThe DKIM signing configuration of your domains, in runs a person starts (optional)

The setup of scheduled runs signs in once with Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All and DelegatedPermissionGrant.ReadWrite.All to create your app registration and grant its read permissions, then takes these three back out of the consent at the end of every setup, renewal and removal.

What we never hold

Not on our servers, not anywhere.

If we do not hold it, it cannot leak from us.

The website and the portal

Nothing loaded from anyone else.

No trackers, no analytics, no advertising, no third-party scripts or fonts.

A strict Content-Security-Policy

Every page, this one included, may run only scripts and styles served by the portal itself, and cannot be framed by another site.

Sessions that end

A sign-in to the portal lasts twelve hours at most, with a code sent to your address and no password. Roles decide who may connect apps, change settings and invite people: owner, operator or viewer.

Found a security problem? Write to security@glacierpointtech.com; how to report a vulnerability says what to send and what to expect.