What Avanoo collects
Data inventory for security, privacy, and procurement reviews — what Avanoo collects, what it never collects, and how collection is controlled.
Avanoo maps SaaS and AI usage from the browser. It is designed to give IT, security, and procurement useful visibility without collecting the content of the activity it observes.
This page is the data inventory to share with a DPO, CISO, works council, or vendor review. Hosting, encryption, subprocessors, and certifications are on Hosting, security, and compliance.
Design in one sentence
Avanoo collects metadata (which professional application was used, when, and under which identity rules you chose), not emails, files, prompts, passwords, or browsing outside the applications you allow.
There is no operating-system agent and no network proxy. The only component installed on a workstation is a browser extension, deployed by your organization on professional devices.
Two controls sit in front of every event
Nothing is produced until both of these are true.
- An allowlist of domains. The extension only treats domains your organization has registered. Any other navigation is ignored before processing: no event is created, and there is no way to reconstruct that visit later. The list is visible and exportable from the platform. Avanoo’s starting catalogue is professional applications only — not personal webmail, consumer social networks, banking, health, trade-union, or job-search sites. You remain in control of the list, including custom URLs for on-premise applications opened in the browser.
- Per-capability switches, off by default. Each monitoring capability has its own organization-level switch. Turning one on or off applies to the whole fleet without an extension update. Changes are logged.
The identity mode (Identified, Pseudonymous, or Anonymous) decides who an event is attached to. It does not expand what the extension is allowed to observe.
Data sources
| Source | What it contributes | Required? |
|---|---|---|
| Browser extension (Chrome, Edge, Brave, Firefox) | Usage, authentication, AI, MCP, extension-inventory, and data-activity metadata from professional browsers | Yes, for discovery |
| Directory ingestion (Microsoft Entra, Google Workspace, Keycloak) | Users, groups or org units, and optionally sign-in or OAuth-consent context | Optional |
| SCIM or CSV | User and group lists when a directory connector is not used | Optional |
| Application catalogue | Compliance metadata about the applications themselves (certifications, hosting region, retention posture). This is product reference data, not employee data | Included |
Directory, SCIM, and CSV integrations enrich identity and grouping. They are not a substitute for the extension, and they are not Avanoo subprocessors — they are systems you already operate.
What is collected
The table below is the inventory. A row only applies when that capability is enabled for your organization.
| Capability | Form stored | Typical purpose |
|---|---|---|
| Allowlisted application domain | Registrable domain only — not the path inside the site | SaaS and Shadow IT mapping |
| Visit time | Timestamp, then aggregated to monthly usage | Frequency of use, license reconciliation |
| Authenticated vs visited | Boolean | Distinguish a real session from a drive-by |
| Browser-install signature | Stable technical ID for that browser install, not a person | Count distinct browsers; stitch events from the same install |
| Professional identity or alias | Real work email, organization-controlled alias, or none — see identity modes below | Attribute usage to a person or a cohort |
| Sign-in metadata | Method type, success or failure, consecutive failures | Detect stuffing attacks, not employee performance |
| MFA metadata | Type of second factor observed | Measure MFA coverage |
| SSO / OAuth / SAML metadata | Identity provider, target application, permissions requested | Check SSO policy and third-party grants |
| Passkeys / WebAuthn | Authenticator type only — the secret is never captured | Inventory phishing-resistant authentication |
| Password reuse and strength | Irreversible, per-user fingerprint computed in the browser. Avanoo never receives the password or the comparison hash | Find reused credentials across apps |
| Installed browser extensions | Name, version, publisher, permissions, state | Browser attack-surface inventory |
| AI usage | Service name, timestamp, prompt count and length, enterprise vs personal account | Shadow AI mapping without prompt content |
| MCP connections | Server name, tool name, authorization signals | See which AI clients were granted the ability to act |
| File and transfer metadata | File name, size, MIME type, destination domain | Investigate uploads to unsanctioned storage or AI tools |
| Clipboard and drag-and-drop | Text length and file count, not content | Data-movement signal |
| Local DLP labels (optional) | Detector labels and counts only, computed in the browser | Flag sensitive-data categories without sending the text |
| Campaign replies | Voluntary answers to questions your administrators send | Adoption and sentiment, Identified mode only |
Catalogue records about applications (security score, certifications, country of processing) are not personal data.
What never leaves the browser — and what is never collected
| Never collected or transmitted | Detail |
|---|---|
| Email, chat, or document content | Page structure may be read in memory to recognise a login screen. Displayed text is not stored or sent |
| AI prompt or response content | Only a count and a character length leave the browser |
| File contents | Name, size, type, and domain only |
| Clipboard contents | Length and type only |
| Passwords | Transformed immediately in the browser. Avanoo never receives plaintext or a reversible hash |
| Keystrokes, screenshots, or webcam/microphone | Not implemented |
| Browser history | Neither read nor stored |
| Navigation off the allowlist | No event is created |
| Personal email addresses in full | When an address is classified as personal, the local part is stripped in the browser before anything is stored (jane.doe@gmail.com becomes @gmail.com) |
| Real-time employee supervision | Events are batched asynchronously. There is no live monitoring screen. In-browser nudges are computed locally from already-deployed policy |
| Individual performance scoring | Finalities are security, compliance, estate management, and awareness — not HR evaluation |
Avanoo does not resell customer data, use it for advertising, or train foundation models on it. Data is processed only to provide the contracted service.
Identity modes
Identity is chosen at deployment and can be changed from the platform without redeploying the extension.
| Mode | What Avanoo receives | What you can see |
|---|---|---|
| Identified | The user’s real professional identity | Named-user analytics, real groups, cross-device reconciliation, individual guidance |
| Pseudonymous | A stable alias your organization generates. Avanoo never receives the mapping back to the person | Per-user and group analytics under the alias |
| Anonymous | A device signature only | Coarse usage by application. Legacy mode — do not choose it for a new deployment without confirming the use case with Avanoo |
No identity mode changes the “never collected” list above.
Use the identity mode comparison with stakeholders, then the privacy model for the responsibilities each mode places on your organization.
Application catalogue
The same catalogue is used by the browser extension, SSO matching, and optional directory signals:
- more than 110,000 professional applications, updated weekly (especially new AI tools);
- customizable per organization, including client-specific URLs for on-premise applications opened in the browser;
- exportable from the platform so a DPO or works council can see exactly which domains are in scope.
Retention
Confirm the values in your contract. The default model is:
| Data | Retention |
|---|---|
| Application visit timestamps | Aggregated to monthly usage within a few days. After that, “who opened which app at 14:32 on Tuesday” no longer exists |
| Security and data-movement events (sign-ins, OAuth/SAML grants, MCP, files, clipboard) | Kept as individual events for a contractual period, because incident investigation needs the precise event. Usage and connection data: 12 months maximum |
| Monthly aggregates | Duration of the contract |
| Platform access and configuration logs | At least 12 months |
| Campaign replies | Duration of the contract, unless a shorter period is agreed |
| Leaver | Deleted on the customer’s instruction |
| End of contract | Returned or destroyed on written instruction; otherwise destroyed within one year of the DPA ending |
Roles
The customer is the controller. Avanoo is the processor under a Data Processing Agreement (GDPR Article 28). Legal basis, employee information, works council consultation, and the record of processing activities sit with the customer. Avanoo assists with data-subject requests and DPIAs using the information it holds.
Related pages
- Hosting, security, and compliance — residency, encryption, subprocessors, certifications.
- Usage modes and privacy — Identified vs Pseudonymous responsibilities.
- Compare identity modes — stakeholder-facing choice.