Limits

What this does not do yet, in the same place as what it does.

This page is part of the terms of service by reference, not marketing beside them. Every row is a capability somebody could reasonably assume, and what is actually true today.

Microsoft 365 and Google Workspace
Microsoft 365 connects today. The Google Workspace connector is built and tested and cannot be used yet: its scopes are restricted, so Google verifies them first, and the Gmail scope additionally needs an independent security assessment. We have not put a date on it here because we do not have one worth holding you to.
How Google Workspace will connect
Through a service account your super administrator authorises once, acting as each person it reads for. An administrator sign-in on its own reaches shared drives and that administrator's own data, which would under-report the rest of your domain without saying so, and we would rather ask for more than report less.
Cloud only
Sonar reads what lives in Microsoft 365 and Google Workspace. It does not reach file shares, laptops, databases or anything on your own network.
Teams
Teams is covered as the files behind it, in SharePoint and OneDrive. Chat and channel messages are not read.
Mailboxes
Mailboxes are in scope only if you put them there, and Microsoft grants mail access tenant-wide. We give your Exchange administrator the script that narrows it to the mailboxes you chose, and we check whether it is in place.
What a finding shows you
Where a value is, not what it says. A finding gives you the page, the sheet or the cell and never the value at it.
Finding one person's data
Sonar maps where categories of personal data live. It does not yet answer 'where is this individual', and that feature is not in this release.
File types
Text-bearing documents, spreadsheets, presentations, PDFs, mail and their attachments. An image with no text layer is recorded as not read rather than counted as clean.
Size
An item above 50 MB is recorded as not read, with the reason, rather than skipped in silence.
How age is measured
By the date an item was last modified, not the date it was last opened. Microsoft's current interface does not report a last accessed date, so a rule about data nobody has touched in years reads the modified date instead, and an item that is read often but never edited looks old.
How fresh a finding is
As fresh as the last scan. Sonar does not subscribe to change notifications in this release, so a file shared this morning appears as shared after the next scan rather than within minutes.
Accuracy
We publish no accuracy figure yet. The measurement harness and its gates are part of the build, and every number we do publish will carry the cases it was measured on.
Region
A workspace is pinned to one region when it is created and cannot be moved afterwards. Frankfurt today, Stockholm by arrangement.
Mail scope

Microsoft grants mail access tenant-wide

There is no Microsoft permission that grants an application a named subset of mailboxes. The control that narrows it is your own application access policy, applied by your Exchange administrator. We give you the script, and we then try to read a mailbox that should be outside the policy and tell you whether we were refused. Mailboxes are in scope only if you put them there, and everything else in the product works without them.

The explainer for a works council
Accuracy

We publish no accuracy figure, and will not until it is measured

Nothing has been measured yet. The measurement harness and its gates are part of the build, and no figure for contextual classification is published before two accepted runs of it exist. When a number is published it carries the cases it was measured on and the limits of that measurement, weakest first. Any figure quoted to you about this product is not one we have published.

What we do keep

The other half of this page is the trust page: what persists, what does not, where it runs, what leaves, and who the sub-processors are.