Avanoo docs
Security and privacy

What Avanoo collects

Data inventory for security, privacy, and procurement reviews — what Avanoo collects, what it never collects, and how collection is controlled.

Avanoo maps SaaS and AI usage from the browser. It is designed to give IT, security, and procurement useful visibility without collecting the content of the activity it observes.

This page is the data inventory to share with a DPO, CISO, works council, or vendor review. Hosting, encryption, subprocessors, and certifications are on Hosting, security, and compliance.

Design in one sentence

Avanoo collects metadata (which professional application was used, when, and under which identity rules you chose), not emails, files, prompts, passwords, or browsing outside the applications you allow.

There is no operating-system agent and no network proxy. The only component installed on a workstation is a browser extension, deployed by your organization on professional devices.

Two controls sit in front of every event

Nothing is produced until both of these are true.

  1. An allowlist of domains. The extension only treats domains your organization has registered. Any other navigation is ignored before processing: no event is created, and there is no way to reconstruct that visit later. The list is visible and exportable from the platform. Avanoo’s starting catalogue is professional applications only — not personal webmail, consumer social networks, banking, health, trade-union, or job-search sites. You remain in control of the list, including custom URLs for on-premise applications opened in the browser.
  2. Per-capability switches, off by default. Each monitoring capability has its own organization-level switch. Turning one on or off applies to the whole fleet without an extension update. Changes are logged.

The identity mode (Identified, Pseudonymous, or Anonymous) decides who an event is attached to. It does not expand what the extension is allowed to observe.

Data sources

SourceWhat it contributesRequired?
Browser extension (Chrome, Edge, Brave, Firefox)Usage, authentication, AI, MCP, extension-inventory, and data-activity metadata from professional browsersYes, for discovery
Directory ingestion (Microsoft Entra, Google Workspace, Keycloak)Users, groups or org units, and optionally sign-in or OAuth-consent contextOptional
SCIM or CSVUser and group lists when a directory connector is not usedOptional
Application catalogueCompliance metadata about the applications themselves (certifications, hosting region, retention posture). This is product reference data, not employee dataIncluded

Directory, SCIM, and CSV integrations enrich identity and grouping. They are not a substitute for the extension, and they are not Avanoo subprocessors — they are systems you already operate.

What is collected

The table below is the inventory. A row only applies when that capability is enabled for your organization.

CapabilityForm storedTypical purpose
Allowlisted application domainRegistrable domain only — not the path inside the siteSaaS and Shadow IT mapping
Visit timeTimestamp, then aggregated to monthly usageFrequency of use, license reconciliation
Authenticated vs visitedBooleanDistinguish a real session from a drive-by
Browser-install signatureStable technical ID for that browser install, not a personCount distinct browsers; stitch events from the same install
Professional identity or aliasReal work email, organization-controlled alias, or none — see identity modes belowAttribute usage to a person or a cohort
Sign-in metadataMethod type, success or failure, consecutive failuresDetect stuffing attacks, not employee performance
MFA metadataType of second factor observedMeasure MFA coverage
SSO / OAuth / SAML metadataIdentity provider, target application, permissions requestedCheck SSO policy and third-party grants
Passkeys / WebAuthnAuthenticator type only — the secret is never capturedInventory phishing-resistant authentication
Password reuse and strengthIrreversible, per-user fingerprint computed in the browser. Avanoo never receives the password or the comparison hashFind reused credentials across apps
Installed browser extensionsName, version, publisher, permissions, stateBrowser attack-surface inventory
AI usageService name, timestamp, prompt count and length, enterprise vs personal accountShadow AI mapping without prompt content
MCP connectionsServer name, tool name, authorization signalsSee which AI clients were granted the ability to act
File and transfer metadataFile name, size, MIME type, destination domainInvestigate uploads to unsanctioned storage or AI tools
Clipboard and drag-and-dropText length and file count, not contentData-movement signal
Local DLP labels (optional)Detector labels and counts only, computed in the browserFlag sensitive-data categories without sending the text
Campaign repliesVoluntary answers to questions your administrators sendAdoption and sentiment, Identified mode only

Catalogue records about applications (security score, certifications, country of processing) are not personal data.

What never leaves the browser — and what is never collected

Never collected or transmittedDetail
Email, chat, or document contentPage structure may be read in memory to recognise a login screen. Displayed text is not stored or sent
AI prompt or response contentOnly a count and a character length leave the browser
File contentsName, size, type, and domain only
Clipboard contentsLength and type only
PasswordsTransformed immediately in the browser. Avanoo never receives plaintext or a reversible hash
Keystrokes, screenshots, or webcam/microphoneNot implemented
Browser historyNeither read nor stored
Navigation off the allowlistNo event is created
Personal email addresses in fullWhen an address is classified as personal, the local part is stripped in the browser before anything is stored (jane.doe@gmail.com becomes @gmail.com)
Real-time employee supervisionEvents are batched asynchronously. There is no live monitoring screen. In-browser nudges are computed locally from already-deployed policy
Individual performance scoringFinalities are security, compliance, estate management, and awareness — not HR evaluation

Avanoo does not resell customer data, use it for advertising, or train foundation models on it. Data is processed only to provide the contracted service.

Identity modes

Identity is chosen at deployment and can be changed from the platform without redeploying the extension.

ModeWhat Avanoo receivesWhat you can see
IdentifiedThe user’s real professional identityNamed-user analytics, real groups, cross-device reconciliation, individual guidance
PseudonymousA stable alias your organization generates. Avanoo never receives the mapping back to the personPer-user and group analytics under the alias
AnonymousA device signature onlyCoarse usage by application. Legacy mode — do not choose it for a new deployment without confirming the use case with Avanoo

No identity mode changes the “never collected” list above.

Use the identity mode comparison with stakeholders, then the privacy model for the responsibilities each mode places on your organization.

Application catalogue

The same catalogue is used by the browser extension, SSO matching, and optional directory signals:

  • more than 110,000 professional applications, updated weekly (especially new AI tools);
  • customizable per organization, including client-specific URLs for on-premise applications opened in the browser;
  • exportable from the platform so a DPO or works council can see exactly which domains are in scope.

Retention

Confirm the values in your contract. The default model is:

DataRetention
Application visit timestampsAggregated to monthly usage within a few days. After that, “who opened which app at 14:32 on Tuesday” no longer exists
Security and data-movement events (sign-ins, OAuth/SAML grants, MCP, files, clipboard)Kept as individual events for a contractual period, because incident investigation needs the precise event. Usage and connection data: 12 months maximum
Monthly aggregatesDuration of the contract
Platform access and configuration logsAt least 12 months
Campaign repliesDuration of the contract, unless a shorter period is agreed
LeaverDeleted on the customer’s instruction
End of contractReturned or destroyed on written instruction; otherwise destroyed within one year of the DPA ending

Roles

The customer is the controller. Avanoo is the processor under a Data Processing Agreement (GDPR Article 28). Legal basis, employee information, works council consultation, and the record of processing activities sit with the customer. Avanoo assists with data-subject requests and DPIAs using the information it holds.

On this page