Browse documentation
AvailableSecurity & Privacy

Windows Agent Privacy

Exact posture scope and explicit exclusions for sensitive endpoint data.

Applies to
OZVO Windows Agent
Product area
Security & Privacy
Audience
Owners and Administrators
Last reviewed
September 17, 2026
Status
Available

Guidance

  • Ten bounded posture sections support security assessment.
  • Passwords, recovery keys, private keys, surveillance data, and arbitrary file contents are excluded.
  • Typed unavailability replaces guessing.

Detailed Posture data

SectionCustomer-safe scope
Device IdentityDevice identifiers needed to distinguish and support the enrolled computer
Operating SystemWindows edition, build, architecture, uptime, locale, and support state
HardwareBounded system, processor, memory, storage-capacity, and adapter facts
Firmware and Hardware TrustFirmware, Secure Boot, and TPM readiness when available
Storage and EncryptionFixed-volume capacity and BitLocker protection state; never recovery material
Windows Update and Patch StateBounded installed-update and pending-restart posture
Installed SoftwareBounded machine-installed software inventory without license keys or uninstall commands
Security ProductsAggregate security-product presence and health evidence
Windows Security ControlsAllowlisted firewall, Defender, service, and control state
Local Accounts and PrivilegeBounded account, group, and active-session security metadata without credentials

Data the Agent does not collect

  • Passwords, password hashes, PINs, or authentication secrets
  • BitLocker recovery passwords, recovery keys, protectors, or key packages
  • Private keys, API keys, bearer tokens, or Windows product keys
  • Browser history, browser cookies, email, messages, or terminal history
  • Keystrokes, screenshots, clipboard contents, microphone, or webcam data
  • Personal documents, arbitrary file contents, directory listings, or a portable-file crawl
  • Raw process command lines, environment-variable values, or generic registry exports

Collection boundaries

Collection is an exact allowlist with record and size bounds. Unsupported or inaccessible evidence is represented as unavailable rather than inferred. Network discovery and Agent posture keep separate provenance even when they correlate to one logical device.

Still need help?Contact Support with the site, device, time, and exact error—never credentials or recovery secrets.Contact Support