Security
Data we collect
Last updated · October 7, 2026
Lutril stores identity and entitlement metadata, not the content of your work.
Data we collect
| Category | What we collect | Source |
|---|---|---|
| Lutril accounts and sessions | Name, work email, role, authentication settings, password hash, failed-login counters, session identifiers and expiry. | Created in Lutril |
| Directory and identity | Email, display name, status, role, admin and external flags, multi-factor state, organizational unit, manager, last sign-in, and the profile photo as raw bytes. The full directory record is also held, encrypted: from Google that is the complete Admin SDK user, including phone numbers, addresses, recovery contacts and custom schemas; from Microsoft it is ten fields only. | Your identity provider |
| HR data | Employee identifier, work email, personal email, job title, department, manager, hire date, contract end date. | Your HR system, when connected |
| Application rosters | Per application and per account: identifier, login, email, display name, role, admin, bot and guest flags, two-factor state, last activity, profile URL, and the vendor's raw record where a connector needs fields our schema has no column for. Where a vendor refuses to disclose an address, the candidate addresses we derived are kept as reviewer evidence. | The applications you connect |
| Access requests and approvals | Requester and approver identities, the application and level requested, the free-text business justification, the approval chain, decisions, timestamps, time to live and expiry. | Lutril, Slack, Teams |
| Access reviews | Campaign scope, reviewer, decisions and reasons. A decision is stored against a per-workspace salted digest of the identity, not the address. The audit snapshot of a completed run holds identities in clear, inside an encrypted blob. | Created in Lutril |
| Provisioning and offboarding | Task state, owner, assignee, notes, checklists, and the source and recipient of a data transfer. Temporary credentials created during provisioning are encrypted and erased once handed over. | Created in Lutril |
| Catalogue and policies | Applications, owners, categories, approval rules, sensitivity levels, launch and documentation URLs. | Configured by you |
| Shadow IT: OAuth grants | Third-party applications authorised against your tenant: client identifier, display name, requested scopes and scope changes, and which employees granted them. | Google Workspace, Microsoft Entra ID |
| Shadow IT: browser extension | Per employee and per catalogued SaaS domain: the registrable domain, a visit count, first and last seen timestamps, and whether a signed-in session was detected. | The extension, installed by your MDM |
| Shadow IT: email discovery | The registrable domain and display name of a vendor that sent a signup email, and the employee it reached. Off by default. | Gmail or Microsoft Graph, on opt-in |
| File exposure and classification | Per file shared by link: file name, type, owner, share scope and role, the share link, and the verdict as a sensitivity level plus a count per detected category. | Google Drive, SharePoint, OneDrive |
| AI prompt protection | Per prompt that contained sensitive data: the AI tool's hostname, a count per detected category, and whether the user was warned or the value masked. | The extension, on the device |
| Non-human identities | Service accounts and workload identities: address, display name, project, roles, privilege tier, key metadata such as identifiers, ages and validity windows, last authentication, and the human principals able to impersonate them. | GCP, AWS, connected vendors |
| AI agents found in code | Repository, branch, commit, file path, line range and hashes, plus sanitised facts: framework, model, tools, triggers. Never the source lines. | GitHub, GitLab, when connected |
| MCP gateway | Per tool call: caller, client, tool name, integration, status, duration and the true byte size of the exchange. Arguments and vendor responses are not kept, with one exception: the Redmine connector records an issue subject on success and the full arguments on error. | The MCP gateway |
| Activity and technical logs | Actor, action, target, IP address, user agent, timestamp and a per-action detail object, plus operational traces and anti-abuse signals. | The platform itself |
| Integration secrets | OAuth access and refresh tokens, API keys and connector credentials you entrust to us. See encryption and secrets. | Entrusted by you |