SecureGovMicrosoft 365 governance, in plain English

Cookies & Data

Last updated: August 26, 2026 · SecureGov.ca
SecureGov is built to hold as little of your data as possible. Our site sets no cookies of its own and uses no advertising and no cross-site tracking — the only things the site itself keeps are two functional preferences (your language and theme); the signed-in dashboard also keeps a small amount of working data in your browser only (see Sections 1 and 3). Our security and hosting provider may set a strictly-necessary cookie to protect the site, and if you choose to subscribe you are taken to our payment provider’s own secure checkout. Because everything is strictly necessary, this site does not use — and does not need — a cookie-consent banner. This page explains the little that is stored, and where.

1. What we store in your browser

We use your browser’s local storage for two strictly necessary, functional settings. These stay on your device, are not sent to us, and are not used to identify or track you.

ItemPurposeWhere
sg_langRemembers your language (EN/FR)Your device
sg_themeRemembers light/dark modeYour device

You can clear these at any time through your browser settings.

The signed-in client dashboard keeps a little more, still only on your device: your Microsoft sign-in session, kept only for your current visit and cleared automatically when you close the tab or sign out; the timing markers for the automatic idle lock; a note of which organization this dashboard is connected to, so it can reconnect; and small per-organization working data — recent posture snapshots, your attestation answers, and any custom pricing you enter. Signing out clears that working data. Your per-organization language and theme, and a small trend history (daily scores and counts, no names), stay on your device so the dashboard looks the way you left it and “since last scan” comparisons keep working; you can clear both at any time through your browser settings. None of this is ever sent to us.

2. What we do not do (and why there is no consent banner)

We do not use advertising or analytics cookies, tracking pixels, fingerprinting, or cross-site trackers. Our hosting provider’s security features (see Section 4) may set a strictly-necessary cookie to protect the site from bots and attacks; such essential cookies do not track you across sites and, like our functional storage, do not require consent. Because we use nothing non-essential, we do not show a cookie-consent banner. If we ever add analytics or another non-essential technology, we will update this page and ask for your consent where the law requires it.

3. Your Microsoft 365 data

When you use the dashboard, it reads your tenant’s security information on a read-only basis and displays it in your browser. This data is processed only to build your view and is not stored on our systems — we keep no database and no copy. You control the access grant and can revoke it in your Microsoft settings at any time.

4. Payments and hosting

A few third-party services support the site, each under its own privacy and cookie policy. The site has no forms, so nothing you type here is processed by a form provider — to reach us, you email us directly.

  • Payments (Stripe). If you subscribe, clicking to pay takes you to Stripe’s own secure checkout page, hosted on Stripe’s domain. Stripe sets its own cookies there under its cookie policy; we do not place Stripe cookies on this site.
  • Hosting and security (Cloudflare). Our site is delivered through Cloudflare, which may set a strictly-necessary cookie and process technical connection data (such as your IP address) to serve the site and protect it from abuse.

This is covered in more detail in our Privacy Policy.

5. More information

For full details on how we handle personal information and your rights, see our Privacy Policy.