AvailableWindows Agent
Windows Agent Privacy
What endpoint posture contains—and the sensitive data it explicitly excludes.
- Applies to
- OZVO Windows Agent
- Product area
- Windows Agent
- Audience
- Owners and Administrators
- Last reviewed
- September 17, 2026
- Status
- Available
Guidance
- Collection is limited to security-relevant posture fields.
- BitLocker state never includes recovery keys or passwords.
- The Agent does not capture browser activity, keystrokes, screens, audio, video, clipboard, or personal documents.
Detailed Posture data
| Section | Customer-safe scope |
|---|---|
| Device Identity | Device identifiers needed to distinguish and support the enrolled computer |
| Operating System | Windows edition, build, architecture, uptime, locale, and support state |
| Hardware | Bounded system, processor, memory, storage-capacity, and adapter facts |
| Firmware and Hardware Trust | Firmware, Secure Boot, and TPM readiness when available |
| Storage and Encryption | Fixed-volume capacity and BitLocker protection state; never recovery material |
| Windows Update and Patch State | Bounded installed-update and pending-restart posture |
| Installed Software | Bounded machine-installed software inventory without license keys or uninstall commands |
| Security Products | Aggregate security-product presence and health evidence |
| Windows Security Controls | Allowlisted firewall, Defender, service, and control state |
| Local Accounts and Privilege | Bounded account, group, and active-session security metadata without credentials |
Data the Agent does not collect
- Passwords, password hashes, PINs, or authentication secrets
- BitLocker recovery passwords, recovery keys, protectors, or key packages
- Private keys, API keys, bearer tokens, or Windows product keys
- Browser history, browser cookies, email, messages, or terminal history
- Keystrokes, screenshots, clipboard contents, microphone, or webcam data
- Personal documents, arbitrary file contents, directory listings, or a portable-file crawl
- Raw process command lines, environment-variable values, or generic registry exports
Collection boundaries
Collection is an exact allowlist with record and size bounds. Unsupported or inaccessible evidence is represented as unavailable rather than inferred. Network discovery and Agent posture keep separate provenance even when they correlate to one logical device.
Still need help?Contact Support with the site, device, time, and exact error—never credentials or recovery secrets.Contact Support →
