Agile Gauge — Security
At a glance
- Your Azure DevOps data stays in your tenant. Agile Gauge reads it read-only, in your browser, and does not copy work item content to AlestaSoftware's servers.
- Seat enforcement happens server-side on every request — not just a screen in the extension.
- Telemetry is aggregate and pseudonymous: no names, no emails, no work item content.
What reaches AlestaSoftware
Only: license records, seat roster (opaque identity descriptors, not names or emails), and aggregate usage/error telemetry. See the Privacy Policy for the full breakdown.
Hosting and data isolation
Agile Gauge's backend runs on infrastructure shared with AlestaSoftware's other products, but in its own isolated database schema — enforced separation so a bug or incident affecting one product cannot reach another product's customer data.
Authentication and access control
- Read-only Azure DevOps scopes only — the Extension cannot modify work items, pipelines, or repository content.
- Seat-based access: an administrator assigns seats; anyone without one is blocked from the Extension's data, verified on the server on every request — this is enforced at the API layer, not just hidden in the UI.
- License activation tokens are bearer credentials, never logged.
Sub-processors
Same as the Privacy Policy: Microsoft Azure DevOps, [payment processor], [cloud host], [email provider].
Incident response
[incident response commitment — not yet defined]
Reporting a security issue
Email [security contact email].