Legal

Terms of Use

Last updated: 31 July 2026

Autopilot Monitor is provided by glueckkanja AG, a German company certified to ISO/IEC 27001 — see the Imprint. Both plans run on the same service and the same infrastructure; the plan determines operating limits, support, and contractual commitments, not how the service works.

The project was created and is maintained by Oliver Kieselbach, who is also the contact for the open-source project and the Community edition. He acts in that role on behalf of glueckkanja AG; he is not a separate contracting party.

Community

Free, publicly available, and maintained by Oliver Kieselbach as an open community contribution. New organizations complete a short activation step after first sign-in. Provided without any commitment by glueckkanja AG as to availability, support, or fitness for a particular purpose. Support is community-based via GitHub.

Pro

Commercial plan under a written agreement with glueckkanja AG. Includes support and reliability commitments, a data processing agreement, higher operating limits, extended retention, and delegated (MSP) administration. Where that agreement differs from these terms, the agreement prevails.

The sections below apply to both plans unless stated otherwise. Plan details are documented under Plans.

Who can use it. Autopilot Monitor requires a Microsoft Entra ID tenant with Intune and registered Autopilot devices. The Community plan is open to anyone with such a tenant — organizations, non-profits, and individuals running their own lab or personal tenant alike. The Pro plan is a commercial agreement and is offered to businesses and organizations acting in a commercial or professional capacity.

Acceptable Use

By using this service, you agree that:

  • The service is used to monitor and troubleshoot Windows Autopilot deployments for devices your organization is entitled to manage.
  • You are responsible for ensuring your use complies with your organization's policies, your works council or employee representation obligations, and applicable law — including informing your users about monitoring where required.
  • Access requires authentication via Microsoft Entra ID, and each tenant's data is accessible only to authorized users of that tenant, or to parties you have granted delegated access.
  • You will not attempt to access another tenant's data, circumvent security controls, or probe the service for vulnerabilities without prior written agreement.
  • You will not use gather rules or any other configuration to collect data unrelated to enrollment diagnostics, or to monitor individual employees.
  • You will not use the service to build a competing product, or resell access without an agreement permitting it.
  • Automated access, including through the MCP integration, stays within the published rate limits and quotas.

Enforcement. Where use threatens the service or other tenants, we respond proportionately. Depending on the situation that may be a warning, reduced rate limits, suspension, or termination — chosen to fit the case, not worked through as a fixed sequence. Where the risk is immediate, access can be restricted at once. A warning is sent where a tenant contact address is on file and time permits.

Security research is welcome and is not a violation of these terms when reported privately. Report findings through GitHub Security Advisories rather than a public issue — see Security & Privacy FAQ for what happens next. Do not access other tenants' data, degrade the service, or run automated scans against production while testing.

Intellectual Property & Licensing

Open source. The Autopilot Monitor source code is published on GitHub under the licence stated in that repository. That licence governs the code — it does not grant rights to the hosted service, its infrastructure, its data, or the Autopilot Monitor name and branding.

Your data stays yours. Enrollment telemetry, configuration, and diagnostics belong to your organization. Using the service grants only the rights needed to operate it for you, as described in the Privacy Policy.

Rules you contribute are covered by the licence grant described under "Your Data, Suspension and Termination" below.

Third-party components remain the property of their respective owners and are used under their own licences; see the attributions below.

Delegated (MSP) Administration

Delegated administration lets a managing organization see a defined set of customer tenants from one place. It is a Pro capability and applies only where access has been granted.

  • Delegated access is read-only and limited to exactly the tenants in scope. Configuration secrets are redacted.
  • A grant is either assigned by platform operators or delegated by the customer's own tenant admin; customer-initiated delegations require approval before they take effect.
  • Every grant, revocation, and disablement is recorded in the managed customer tenant's audit log, so a customer can always determine who holds access to their data.
  • A managing organization is responsible for having the necessary data protection agreements in place with the customers it manages.
  • Access can be revoked at any time by the customer or by platform operators and takes effect within seconds.

Availability, Support and Data

Community plan: provided "AS-IS", no warranty

The Community plan is provided free of charge, "AS-IS", and without warranty of any kind, express or implied, including the implied warranties of merchantability and fitness for a particular purpose. The platform is under continuous, active development: updates are frequent, availability is not guaranteed, and data structures may change. Production use is permitted and intended — with that trade-off understood.

Availability. The Community plan carries no uptime or availability commitment; interruptions, maintenance, and changes can occur without prior notice. The Pro plan carries the availability commitments set out in its agreement.

Support. Community support is best-effort via GitHub issues, provided by the project maintainer and the community, with no guaranteed response or resolution time; built-in rules and IME log patterns are community-maintained. Pro support follows the response commitments in its agreement.

Data durability. Autopilot Monitor is a monitoring system, not a system of record. Configuration, authorization, and rule data is backed up daily; session and event telemetry is time-bounded operational data and is not backed up. Retain anything you need for compliance or reporting purposes in your own systems.

Liability. To the extent permitted by law, glueckkanja AG is not liable for indirect, incidental, special, consequential, or punitive damages, or for loss of data, profit, or business, arising from use of or inability to use the service. For the Community plan, which is provided free of charge, liability is limited to intent and gross negligence. Liability for injury to life, body or health and under mandatory statutory provisions remains unaffected. For the Pro plan, the liability provisions of the written agreement apply.

Use at your own risk. The service reports on enrollments; it does not perform them. Operational decisions you take based on its output remain your responsibility.

Your Data, Suspension and Termination

Ownership. Your enrollment telemetry remains yours. Autopilot Monitor processes it to provide the service, as described in the Privacy Policy.

Your controls. You set the retention period, delete individual sessions, and offboard your tenant entirely at any time — no support ticket required.

Rules you contribute. Analyze rules, gather rules, and IME log patterns you author are detection definitions, not device data. By creating them you grant a non-exclusive, royalty-free right to retain them and to include them in the shared community rule pool, so that other organizations can benefit from a detection you built. This is the reciprocal side of a product whose built-in rules are community-maintained. You keep the right to use your own rules however you like, and you can request removal from the pool at any time.

Suspension. Access may be suspended where use threatens the integrity, security, or availability of the service or of other tenants — for example abusive request volumes or attempts to reach other tenants' data. Where circumstances permit, notice is given first.

Termination. You may stop using the service and offboard at any time. For the Community plan, the operator may discontinue the service or an individual tenant's access; reasonable advance notice will be given except where security requires immediate action. Pro termination follows its agreement.

After offboarding. Your tenant's data is removed through a verified multi-phase cascade. Product feedback you submitted, and custom rules and IME log patterns you authored, are intentionally retained — neither contains enrollment telemetry or personal data. Both are removed on request.

Security and Transparency

The security architecture, data residency, external services, retention and deletion behaviour, and an explicit statement of what the service does not do are published in the Security & Privacy FAQ. A signed data processing agreement is part of the Pro plan.

Third-Party Data Sources & Attributions

The vulnerability correlation feature uses the following external data sources to identify known vulnerabilities in installed software. These are inbound reference-data pulls — no customer data is sent to them.

National Vulnerability Database (NVD)

This product uses the NVD API but is not endorsed or certified by the NVD.

The NVD is maintained by the National Institute of Standards and Technology (NIST). CVE and CPE data is sourced from the NVD API 2.0. For more information, visit nvd.nist.gov.

CISA Known Exploited Vulnerabilities (KEV) Catalog

Actively exploited vulnerability data is sourced from the CISA KEV Catalog maintained by the Cybersecurity and Infrastructure Security Agency. For more information, visit cisa.gov.

Microsoft Security Response Center (MSRC)

Microsoft-specific vulnerability data is sourced from the MSRC Security Update Guide API. For more information, visit msrc.microsoft.com.

Changes and Governing Law

Changes. These terms may be updated; the "last updated" date above reflects the current version, and material changes are announced through the service announcements in the portal. Continued use after a change constitutes acceptance.

Governing law. These terms are governed by German law. For the Pro plan, the governing-law and venue provisions of the written agreement apply.

Severability. If a provision is found unenforceable, the remaining provisions stay in effect.

Contact. Company details are in the Imprint. For the project and the Community edition, reach the maintainer via LinkedIn or open a GitHub issue.