Overview
Data protection in Turbo360 covers how the platform collects, stores, processes, and retains data from your connected Azure subscriptions. Understanding these practices helps your organization meet compliance requirements and make informed decisions about data residency and handling.
Business value
Knowing how Turbo360 handles your data allows your security and compliance teams to assess risk accurately, meet contractual obligations, and configure retention and access controls with confidence.
How it works
Data collected by Turbo360
Turbo360 collects and processes the following categories of data from your connected Azure subscriptions:
- Cost and billing data: resource-level consumption data, billing periods, subscription costs, and reservation utilization retrieved from Azure Cost Management.
- Resource metadata: resource names, types, tags, regions, and configuration attributes used for cost analysis, documentation, and monitoring.
- Monitoring telemetry: availability states, metric values, log query results, and alert events collected from Business Applications and Business Activity Monitoring (BAM) modules.
- Audit data: user actions performed within the Turbo360 portal, including role changes, resource configuration updates, and subscription management events.
- Authentication data: user identity information (name, email, tenant ID) passed via Microsoft Entra ID during authentication. Turbo360 does not store passwords.
Data storage and residency
- Turbo360 stores collected data in Azure-hosted infrastructure.
- For organizations using private hosting, data storage occurs within your own Azure subscription and infrastructure. You retain full control over storage accounts, regions, and retention policies.
- Turbo360 does not transfer your subscription data to third-party services outside the platform's operational scope, with one exception: AI Agents and Explain with AI features send a subset of resource data to Azure OpenAI to generate responses. This applies only when these features are actively used. See AI features and third-party data processing for full details.
Data retention
- Cost and monitoring data is retained for a defined period to support trend analysis, anomaly detection, and reporting.
- User logs are retained to support compliance review and incident investigation.
- When a subscription is disconnected from Turbo360, associated data is removed completely.
Encryption
- Data at rest is encrypted using Azure Storage Service Encryption (SSE) with platform-managed keys by default.
- Data in transit between Turbo360 services and your Azure subscription is encrypted using TLS 1.2 or higher.
- Authentication tokens issued during Entra ID SSO sessions are transmitted over HTTPS and are not persisted beyond the session duration.
Access to your data
- Turbo360's engineering and support teams access customer data only when required to investigate a reported issue, and only with appropriate authorization.
Private hosting data isolation
Organizations using private hosting operate a fully isolated Turbo360 instance within their own Azure subscription. In this configuration, no data leaves your tenant boundary. You are responsible for backup, retention, and encryption key management for all data stored within your private instance.