Agile Gauge: Security
At a glance
- Your Azure DevOps data stays in your tenant. Agile Gauge reads it read-only, in your browser, and does not copy work item content to Alesta Software's servers.
- Seat enforcement is checked with our licensing service every time Agile Gauge opens: not just a screen in the extension. Licenses are signed, so they cannot be forged in the browser.
- Usage telemetry is aggregate daily counts: no organization, no person, no work item content.
- We store no names or email addresses of your users, and our service logs keep no client IP addresses.
What reaches Alesta Software
Only: license and payment records, the seat roster, the Agile Gauge admin list, the support tickets you open, and aggregate usage counts. Each person on the seat roster or the admin list is kept only as a keyed one-way hash and a reference we generate (it starts with USR-): never a name, email address or Azure DevOps identity ID. Agile Gauge shows names by asking your own Azure DevOps, so they never reach us. See the Privacy Policy for the full breakdown.
Hosting and data isolation
Agile Gauge's backend runs on infrastructure shared with Alesta Software's other products, but in its own isolated database schema: enforced separation so a bug or incident affecting one product cannot reach another product's customer data.
Authentication and access control
- Read-only Azure DevOps scopes only: the Extension cannot modify work items, pipelines, or repository content.
- Seat-based access: after the trial, an administrator assigns seats; anyone without one is blocked from the Extension's data. Every call to our licensing service carries the caller's Azure DevOps identity, which the service verifies with Azure DevOps before answering. The service keeps only the keyed hash described above, never the identity itself.
- License activation tokens are bearer credentials, never logged.
Sub-processors
Microsoft Azure (our licensing service and database, in the Central US region), Paddle (payments, as Merchant of Record), Resend (license-key email, and ticket notices to our own support address) and Cloudflare (DNS). The full list, with what each one receives, is on the sub-processors page.
Incident response
If we confirm a security incident that affects customer data, we notify the affected customers through a notice in the Extension and on our website, without undue delay and within the time the law requires, with what happened, what data was involved and what we are doing about it, and we notify the authorities where the law requires.
Reporting a security issue
Email [email protected].