Auditex
Privacy Policy
Auditex is published by MAGRATHEAN UK LTD (“Magrathean”). This notice explains what Auditex does with data. The Magrathean privacy policy covers everything else, including your rights and how to contact us.
Auditex runs on your own machine. It is not a hosted service: Magrathean does not receive your tenant data, audit evidence or credentials. Auditex connects only to the Microsoft 365 or Google Workspace tenant you are authorised to audit, using your own sign-in, and to any AI tool you choose to connect to its local MCP server. It has no analytics or advertising SDK.
The Auditex website, magrathean.uk/solutions/auditex/, separately uses Google Analytics and Cloudflare Web Analytics to measure page visits and link clicks, active by default. That is website measurement, not app data collection; it does not receive data from Auditex.
On your device
Auditex writes collected evidence, reports and customer packs to the output directory you choose. Authentication material is kept in the local auth files you configure, outside the repository. Delete the output directory, or the auth files, to remove that data.
What leaves your device
| Data | Goes to | Why | When |
|---|---|---|---|
| Read-only audit requests, using your own sign-in | Microsoft Graph, Microsoft Entra ID and related Microsoft 365 endpoints | Collect the evidence your audit or probe command requests | Every Microsoft 365 audit or probe run |
| Read-only audit requests, using your own sign-in | Google Workspace APIs (Admin SDK, Reports, and related endpoints) | Same, for a Google Workspace tenant | Only when you use the optional google extra with your own credentials |
| A notification issue (title and summary) | GitHub, via the GitHub API | Open a tracking issue for a finding | Only when you set AUDITEX_GITHUB_TOKEN and AUDITEX_GITHUB_REPO |
| Whatever you choose to share in a session | The AI tool you connect to Auditex’s local MCP server | Let that tool read audit output and drive guided flows | Only when you run auditex-mcp and connect an AI tool to it |
Auditex does not read message bodies or file content, and its public audit surface does not write to the tenant you audit. The separate tenant-bootstrap/ lab kit is a writable tool for your own test environments, outside the audited product’s scope; see the security and privacy model for detail.
Keeping and deleting data
Audit evidence, reports and packs stay in the output directory you chose until you delete them. Auditex keeps no copy elsewhere.
Changes
We update this notice when Auditex changes and show the date at the top.
Contact
Questions: contact+auditex@magrathean.uk.