Security Overview
Last reviewed: June 24, 2026
Overdrive Workspace is a read-only Google Workspace™ Drive™ exposure audit tool for Workspace administrators. Connecting it means trusting it with visibility across your organization, so this page sets out exactly what that access is — and what it isn't. For the full legal detail, see our Privacy Policy and Terms of Service.
Read-only. Always.
Overdrive requests no write access. It cannot change, delete, move, or share anything in your workspace. It can only look.
Metadata only — never your file contents.
It reads sharing events, app grants, and directory information. It never opens, reads, or stores the contents of your files.
Your logs stay yours.
Audit events are turned into findings and then discarded — we don't keep a copy of your raw logs. Google's audit log stays the source of truth; Overdrive is just a lens over it.
Encrypted and isolated.
Your data is encrypted and kept separate from every other workspace. Your access token is stored server-side, encrypted, and never touches the browser.
No selling. No ads. No training.
We don't sell your data, show ads, or use your workspace data to train AI models. People on our side don't look at it except when you ask for support or to investigate a security issue.
What Overdrive can access
Overdrive connects through Google's OAuth 2.0 with the minimum scopes needed for the audit. The audit product requests read-only scopes only — there is no write access of any kind.
- Audit reports (read-only) — Google Workspace™ audit log events, specifically Drive™ sharing events and OAuth application authorization events, to detect external exposure and third-party app grants.
- Directory (read-only) — user names, email addresses, organizational units, 2-step verification status, and suspension status, used to tell internal from external principals and surface exposure by suspended or departed users.
- Verified domains (read-only) — the domains registered to your organization, used to classify sharing recipients as internal or external.
Explicitly never accessed: file contents, Gmail™ messages, calendar events, contacts, or anything not listed above. The full-Drive write scope used for optional remediation is not requested by the audit product; if remediation is ever enabled, that scope is requested separately with a clear explanation.
What we store — and what we don't
Overdrive follows a "scan broadly, store narrowly" principle: we keep only the derived findings needed to show you exposure, never raw audit logs or file contents.
We store
- Workspace record — organization name, verified domains, connection status.
- Scan summaries — time, scope, and totals for each audit scan.
- Risky-file findings — file ID, title, sharing type, external principals, and risk score for files with external or public exposure.
- External principals and per-user risk aggregates.
- An encrypted OAuth refresh token — server-side only, never exposed to the browser.
We do not store
- Raw Google audit log events — processed transiently, then discarded.
- Any file contents.
- Private, internal-only files with no external exposure.
- Full directory snapshots — only what's needed to classify sharing recipients.
Encryption and token handling
All data is encrypted in transit (TLS) and at rest. Your OAuth refresh token — the credential Overdrive uses to call Google APIs on your behalf — is encrypted at rest, stored server-side only, and never transmitted to the browser. We apply technical and organizational measures including access controls and secrets management.
No transmission over the internet is ever completely secure, and we can't guarantee absolute security; this page describes the measures we take, not a guarantee against all risk.
Tenant isolation
Each connected workspace's data is isolated from every other workspace. No workspace can read another workspace's findings, principals, or tokens.
Infrastructure and sub-processors
Derived data is stored in the EU (Frankfurt, Germany). We use the following sub-processors, each bound by a data processing agreement. The authoritative, maintained list lives in the Privacy Policy.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, auth, storage | EU Central — Frankfurt, Germany |
| Vercel, Inc. | Application hosting, serverless functions | United States (edge globally) |
| Google LLC | Google APIs (data source); Google Cloud Platform™ for OAuth | United States |
| Lemon Squeezy, LLC | Payment processing and billing (Merchant of Record) | United States |
Retention and deletion
Derived findings are retained while your workspace stays connected, or until you ask us to delete them. When you disconnect or delete your account:
- Your OAuth refresh token is immediately revoked and deleted.
- All derived findings, aggregates, and workspace records are deleted within 30 days.
- Only anonymized aggregate statistics that cannot be tied back to your organization may be retained.
You can request deletion at any time at info@overdrive.tools.
Data residency and GDPR
Derived data is stored in the EU (Frankfurt). Overdrive Tools is headquartered in Israel, which the European Commission recognises as providing an adequate level of data protection, so transfers from the EEA are permitted without additional safeguards; transfers to US sub-processors are governed by standard contractual clauses or equivalent. We can provide a Data Processing Agreement on request. Full detail, including data-subject rights, is in the Privacy Policy.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you've found a security issue or a potential incident, email info@overdrive.tools with the details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure.