Read-only by design. Encrypted by default.
SeatCheck reads sign-in events from your identity provider to show which SaaS tools your team actually uses. That is the only thing it reads, and it can never change anything in your stack.
Verified and assessed
CASA Tier 2
Independent third-party security assessment under Google's Cloud Application Security Assessment program.
Microsoft verified publisher
Our Microsoft Entra app carries Microsoft's verified-publisher badge for seatcheck.ai.
How we handle your data
Read-only by design
SeatCheck can read sign-in events from your identity provider. It cannot modify users, permissions, or anything else in your stack.
Minimum-necessary scopes
We only request the OAuth scopes needed to read sign-in audit logs. Nothing more. Review the exact scopes before you connect.
Credentials encrypted
OAuth tokens are encrypted at rest with AES-256-GCM and never appear in logs. Auth, webhook, and signup endpoints are rate-limited.
No content access
We never see message contents, file contents, or what your team does inside any tool — only that they signed in.
Limited data scope
We store: timestamp, employee email, display name, tool name, IdP source. That's the entire list.
Disconnect anytime
One click in Settings revokes our access. Your IdP will confirm the revocation.
Infrastructure
SOC 2 Type I on the roadmap. Hosted on Vercel (app), Neon (Postgres), Upstash (Redis), and Render (worker) — all US, all SOC 2 Type II. For security questions, email security@seatcheck.ai.
Privacy and your rights
Read our Privacy Policy for the full detail on what we collect and why, or submit a privacy request to access or delete your data.