Data category | Details | Purpose |
Account credentials | Account credentials provided by the enterprise administrator, including user account, password, mobile number, and email. Login user, hostname, device type, IP address, operating system, last login time, last logout time. | This verifies the user’s identity and enables access to the Feature’s web console. |
Network gateway data | Proxy Mode (Global Proxy): device network information (e.g., NIC address, IP address, routing information, PID and process name of applications accessing the network). Proxy Mode (Browser Proxy): device network information (e.g., NIC address, IP address, system proxy settings, PID and process name of applications accessing the network). Proxy Mode (WFP Proxy): device network information (e.g., NIC address, IP address, PID and process name of applications accessing the network). Account credentials (Token / Secret); identity identifiers (account / UID); network identifiers (IP / MAC); location information (GeoIP / country); access behaviour (resource / URL / domain / port); endpoint hardware identifiers (host_id / GUID). | This provides zero-trust network access, identity authentication, traffic encryption, access authorisation and behavioural auditing for access to enterprise business resources in accordance with customer instructions and policies. |
Data category | Details | Purpose |
Endpoint / software information | Endpoint information: endpoint name, MAC address, SN (serial number), network IP, client version, endpoint model, CPU, motherboard, memory capacity, primary hard drive, graphics card, network adapter, monitor, sound card, OS name, OS build number, system architecture; allowlists/blocklists for processes and operations configured by the administrator. Software information: list of installed software, software details (name, version, runtime), currently running processes, device OS version, IP address, vulnerability remediation information, service information, local port information, disk information, domain-join information, registry information, and software allowlists/blocklists configured by the administrator. | This verifies whether the device complies with compliance detection policies configured by the enterprise user and alerts on associated risks. |
Environment and vulnerability remediation information | Environment information: device environment information, network environment information, and application environment information (collected prior to client login). Vulnerability remediation: vulnerability type, patch ID, detection time, and handling result. | This detects malicious programmes and device vulnerabilities, and supports virus removal and vulnerability remediation. |
Document / watermark management information | Work-file operation records (including outbound transfer logs); screen-recording permission (used solely to configure watermark opacity, font, and colour when the enterprise user enables screen watermarking). | This supports document management policies and screen watermark configuration where enabled by the enterprise user. |
Data loss prevention information | Work-file operation records; outbound work files (when a blocking policy is triggered); device screenshot data (when the enterprise user enables the screen-capture forensics policy). | This protects corporate data assets by recording work-file operations, blocking outbound work files and collecting screenshots where configured by the enterprise user. |
Network gateway data | Proxy Mode (Global Proxy): device network information (e.g., NIC address, IP address, routing information, PID and process name of applications accessing the network). Proxy Mode (Browser Proxy): device network information (e.g., NIC address, IP address, system proxy settings, PID and process name of applications accessing the network). Proxy Mode (WFP Proxy): device network information (e.g., NIC address, IP address, PID and process name of applications accessing the network). Account credentials (Token / Secret); identity identifiers (account / UID); network identifiers (IP / MAC); location information (GeoIP / country); access behaviour (resource / URL / domain / port); endpoint hardware identifiers (host_id / GUID). | This provides zero-trust network access, identity authentication, traffic encryption, access authorisation and behavioural auditing for access to enterprise business resources in accordance with customer instructions and policies. |
Cloud-Based Virus Scanning and EDR Information | Software processes; processes of malicious programmes being terminated; executable programmes; software IP address; software domain name. Where the Cloud-Based Virus Scanning User Plan is enabled or triggered, relevant security threat information may be uploaded for analysis, including suspected executable programmes, software IP addresses, software domain names, file hash information and URL information. | This enables cloud-based threat analysis where local virus databases lack sample characteristics for suspected threats, and supports updates to Tencent security services and those of its affiliates. |
AI Security Analysis Data | Prompt / AI input content; skill samples uploaded to the cloud for in-depth analysis; AI invocation scripts and commands; operation audit (time / endpoint / account / handling result); employee account; user name; basic endpoint attributes (IP / MAC / OS / user name). | This supports AI application security management, including asset inventory, malicious Skill detection, vulnerability and attack surface analysis, runtime protection, sandbox controls and operational behaviour auditing according to customer-configured policies. |
Data category | Details | Purpose |
Cleanup action logs | Report time, endpoint time, endpoint user name, employee account, user name, endpoint ID, endpoint IP, MAC address. | This records log information regarding junk cleanup actions in the console. |
Endpoint information | Endpoint name, MAC address, SN (serial number), network IP, client version, endpoint model, CPU, motherboard, motherboard serial number, memory, primary hard drive, graphics card, network adapter, monitor, sound card, hardware manufacturer. | This supports device binding, management and unbinding based on device information and permissions granted during use of the Feature. |
Software information | List of installed software, software information (version and runtime), and software registry information. | This checks whether specific software is installed, provides uninstallation information and displays software version information. |
Login information | Login user, hostname, device type, IP address, operating system, last login time, last logout time. The third-party product will provide the enterprise user with your name (or nickname), account, mobile number, and email registered with that third-party product (subject to what the third-party product publicly discloses and provides). | This verifies user identity and enables account login or SSO login as configured by the enterprise user. |
Endpoint / software information | Endpoint information: endpoint name, MAC address, SN (serial number), network IP, client version, endpoint model, CPU, motherboard, memory capacity, primary hard drive, graphics card, network adapter, monitor, sound card, OS name, OS build number, and system architecture. Software information: list of installed software, software details (name, version, runtime), currently running processes, device OS version, IP address, vulnerability remediation details, service information, local port information, disk information, domain join status, and registry information. | This verifies whether the device complies with compliance detection policies configured by the enterprise user and alerts on associated risks. |
Junk file cleanup data | Collected via user input and on the client. Device information (GUID); cache files of audio streams, videos, and documents; list of installed software; software information (name, version, runtime); registry data; web browsing history; software usage records; cookies; and download records. The above information is collected and processed locally on the endpoint only. | This cleans up junk files on the device. |
Document guardian data | Document files (collected and processed locally on the endpoint only). | This supports document protection, recovery and decryption. |
Software information | List of installed software; software information (name, version, runtime); currently running processes; and system configuration information (registry entries for startup items, services, scheduled tasks, and plugins). | This displays and manages device startup items. |
Environment information | Device environment, network environment, and application environment information. | This supports local client diagnostics. |
Software information | List of installed software; software information (name, version, runtime); software pop-up information; and process information. The above information is collected and processed locally on your endpoint only. | This identifies whether software pop-ups are advertising windows and provides the user with the option to block them. |
Device network information | Device network information (NIC address, IP address, routing information, and the PID and process name of applications accessing the network). | This modifies device routing, proxies device network traffic and forwards traffic according to enterprise user policy configuration. |
Device network information | Device network information (NIC address, IP address, system proxy settings, and the PID and process name of applications accessing the network). | This modifies device proxy configuration, proxies browser network traffic and forwards traffic according to enterprise user policy configuration. |
Device network information | Device network information (NIC address, IP address, and the PID and process name of applications accessing the network). | This forwards network traffic according to enterprise user policy configuration. |
Network gateway data | Proxy Mode (Global Proxy): device network information (e.g., NIC address, IP address, routing information, PID and process name of applications accessing the network). Proxy Mode (Browser Proxy): device network information (e.g., NIC address, IP address, system proxy settings, PID and process name of applications accessing the network). Proxy Mode (WFP Proxy): device network information (e.g., NIC address, IP address, PID and process name of applications accessing the network). Account credentials (Token / Secret); identity identifiers (account / UID); network identifiers (IP / MAC); location information (GeoIP / country); access behaviour (resource / URL / domain / port); endpoint hardware identifiers (host_id / GUID). | This provides zero-trust network access, identity authentication, traffic encryption, access authorisation and behavioural auditing for access to enterprise business resources in accordance with customer instructions and policies. |
Virus Scanning and Removal Data | Virus Scanning and Removal: endpoint model, list of installed software, list of currently running software, registry information, audio stream files, video files, and document files. When the enterprise user enables the "Cloud-Based Virus Scanning User Programme" in the management backend: locally inspected processes of running software and security threat information regarding suspected viruses/Trojans (including suspicious executables, software IP addresses, and software domain names). Vulnerability type, patch ID, detection time, and handling result. | This detects malicious programmes and device vulnerabilities, and supports virus removal and vulnerability remediation. |
Real-time Protection | Employee Account, User Name, User Directory, Device Name, Device ID, Device Group, Device IP, MAC Address, Risk Name, Detection Time, Attack Time, Command Line, Action Result | This provides real-time endpoint protection against threats from downloads, chat file transfers and USB drives, with enterprise-configured controls for system protection, social engineering defence, lateral movement prevention, document recovery and endpoint deception. |
Data category | Details | Purpose |
Login information | Login user, hostname, device type, IP address, operating system, last login time, last logout time. The third-party product will provide the enterprise user with your name (or nickname), account, mobile number, and email registered with that third-party product (subject to what the third-party product publicly discloses and provides). | This verifies user identity and enables account login or SSO login configured by the enterprise user. |
Endpoint information | Endpoint model, CPU, motherboard, motherboard serial number, memory, primary hard drive, graphics card, network adapter, monitor, sound card, SN (serial number), MAC address, and hardware manufacturer. | This supports device binding, management and unbinding based on device information and permissions granted during use of the Feature. |
Software information | List of installed software, software information (version and operating time), and software registry information. | This checks whether specific software is installed, provides uninstallation information and displays software version information. |
Device, network, and software information | Device OS version; device network information (e.g., NIC address, IP address); status of the device firewall and System Integrity Protection (SIP); list of installed software and software information (name, version); information on currently running processes/services; domain-join information; and local port information. | This verifies whether the device complies with compliance detection policies configured by the enterprise user and alerts on associated risks. |
Personal user information | Personal user information (including name or nickname, mobile number, department, etc.); device information (device name, device model, client version, device platform, network IP, ID information, etc.); and authentication information (authentication actions, additional parameters, authentication factors / authentication methods, etc.). Personal usage behaviour: user login, endpoint security checks, access to enterprise intranet resources, client upgrade records, etc. Personal information submitted by, or requested from, the data subject by the enterprise user, including name, gender, mobile number, and ID number. | This allows us to provide you with the Feature, including supporting continuous trusted authentication, access policy management and log auditing based on information submitted or generated during use of the Feature. |
Environment information | Device environment, network environment, and application environment information. | This supports local client diagnostics. |
File management system information | Work-file operation records; process start/exit information; process network-access information; and endpoint command-line operation records. Where necessary, risky processes are terminated and virus-infected files are quarantined. | This manages corporate work files and records operation logs where the enterprise user enables file control or screen watermarking. |
Data loss prevention information | Work-file operation records; outbound work files are intercepted. When the enterprise user further enables the screen-capture forensics policy, the enterprise user will additionally collect device screenshots and the outbound work files. | This prevents data leakage by enforcing enterprise-configured data classification, grading and interception policies, including screenshot evidence collection where enabled. |
Device network information | Device network information (NIC address, IP address, routing information, and the PID and process name of applications accessing the network). | This modifies device routing, proxies device network traffic and forwards traffic according to enterprise user policy configuration. |
Device network information | Device network information (NIC address, IP address). | This modifies device proxy configuration, proxies browser network traffic and forwards browser network traffic according to enterprise user policy configuration. |
Network gateway data | Proxy Mode (Global Proxy): device network information (e.g., NIC address, IP address, routing information, PID and process name of applications accessing the network). Proxy Mode (Browser Proxy): device network information (e.g., NIC address, IP address, system proxy settings, PID and process name of applications accessing the network). Proxy Mode (WFP Proxy): device network information (e.g., NIC address, IP address, PID and process name of applications accessing the network). Account credentials (Token / Secret); identity identifiers (account / UID); network identifiers (IP / MAC); location information (GeoIP / country); access behaviour (resource / URL / domain / port); endpoint hardware identifiers (host_id / GUID). | This provides zero-trust network access, identity authentication, traffic encryption, access authorisation and behavioural auditing for access to enterprise business resources in accordance with customer instructions and policies. |
Endpoint and software information | Endpoint model, list of installed software, list of currently running software, audio stream files, video files, and document files. | This helps determine whether the device contains malicious programmes such as viruses, Trojans or ransomware. |
Data category | Details | Purpose |
Endpoint / software information | Endpoint information: endpoint name, MAC address, SN (serial number), network IP, client version, endpoint model, CPU, motherboard, memory capacity, primary hard drive, graphics card, network adapter, monitor, sound card, OS name, OS build number, system architecture; allowlists/blocklists for processes and operations configured by the administrator. Software information: list of installed software, software details (name, version, runtime), currently running processes, device OS version, IP address, vulnerability remediation information, service information, local port information, disk information, domain-join information, registry information, and software allowlists/blocklists configured by the administrator. | This verifies whether the device complies with compliance detection policies configured by the enterprise user and alerts on associated risks. |
Information for security scanning | (1) Application information for anti-virus protection: device information (GUID), list of installed apps, MD5 of installation packages. (2) Network information for network protection: device information (LAC, cell ID, MCC, MNC, network type), nearby Wi-Fi, SSID and BSSID of the current Wi-Fi connection, current IP address, routing table, selected port information (22, 23, 80, 8080, 136, 139, 445, 3389), and system DNS information. (3) System information for system protection: OS name, OS version, kernel version, and ROM version. | This checks installed software for viruses, malware and other risks; current network connection for risks; and the device system for security vulnerabilities and risk of being rooted. |
Device information | CPU, GUID, memory, OS version, OS name, and carrier information. | This supports device binding, management and unbinding based on device information and permissions granted during use of the Feature. |
Network protection information | SSID and BSSID of the current Wi-Fi connection; system DNS address. | This detects whether the current network connection presents security risks. |
System protection information | System version, device name. | This detects system-level security risks such as jailbreak/root or other system vulnerabilities. |
Biometric authentication results | Gesture password (stored locally only, not uploaded); results of the system’s facial recognition; results of the system’s fingerprint recognition (the system’s recognition interface is invoked only when setting or verifying the password, and only the recognition result is obtained — no raw facial or fingerprint data is collected). The Feature will request VPN permission to establish an encrypted channel for accessing the enterprise user’s intranet applications. | This verifies user identity for secure connection. |
Clipboard data | Clipboard data (processed locally on the device only). | This scans clipboard information locally during paste operations to provide quick text input. |
Account credentials | User account, name (or nickname), password, mobile number, and email. These items serve as credentials for logging in and using the service, and may be provided by the enterprise administrator. | This verifies user identity and enables login to the Feature. |
Third-party account information | When using a third-party product (such as WeCom, WeChat, Feishu, or DingTalk) to log in to the Feature via Single Sign-On, the third-party product provides the enterprise user with the following: name / nickname, account, mobile number, and email (subject to what the third-party product publicly discloses and provides). | This enables SSO login through third-party products configured by the enterprise user. |
Network gateway data | Proxy Mode (Global Proxy): device network information (e.g., NIC address, IP address, routing information, PID and process name of applications accessing the network). Proxy Mode (Browser Proxy): device network information (e.g., NIC address, IP address, system proxy settings, PID and process name of applications accessing the network). Proxy Mode (WFP Proxy): device network information (e.g., NIC address, IP address, PID and process name of applications accessing the network). Account credentials (Token / Secret); identity identifiers (account / UID); network identifiers (IP / MAC); location information (GeoIP / country); access behaviour (resource / URL / domain / port); endpoint hardware identifiers (host_id / GUID). | This provides zero-trust network access, identity authentication, traffic encryption, access authorisation and behavioural auditing for access to enterprise business resources in accordance with customer instructions and policies. |
Data category | Details | Purpose |
Endpoint / software information | Endpoint information: endpoint name, MAC address, SN (serial number), network IP, client version, endpoint model, CPU, motherboard, memory capacity, primary hard drive, graphics card, network adapter, monitor, sound card, OS name, OS build number, system architecture; allowlists/blocklists for processes and operations configured by the administrator. Software information: list of installed software, software details (name, version, runtime), currently running processes, device OS version, IP address, vulnerability remediation information, service information, local port information, disk information, domain-join information, registry information, and software allowlists/blocklists configured by the administrator. | This verifies whether the device complies with compliance detection policies configured by the enterprise user and alerts on associated risks. |
Information for security scanning | (1) Application information for anti-virus protection: device information (GUID), list of installed apps, MD5 of installation packages. (2) Network information for network protection: device information (LAC, cell ID, MCC, MNC, network type), nearby Wi-Fi, SSID and BSSID of the current Wi-Fi connection, current IP address, routing table, selected port information (22, 23, 80, 8080, 136, 139, 445, 3389), and system DNS information. (3) System information for system protection: OS name, OS version, kernel version, and ROM version. | This checks installed software for viruses, malware and other risks; current network connection for risks; and the device system for security vulnerabilities and risk of being rooted. |
Device information | Device information: manufacturer, brand, model, name, MAC address. System information: OS name, OS version, kernel version, ROM version, Bluetooth MAC, Android ID, and device SN (hardware serial number). | This supports device binding, management and unbinding based on device information and permissions granted during use of the Feature. |
Device information (GUID) | Device information (GUID); list of installed apps; MD5 of installation packages. | This detects whether installed applications present virus, malware or other application security risks. |
Device network information | Device information (LAC, cell ID, MCC, MNC, network type); nearby Wi-Fi; SSID and BSSID of the current Wi-Fi connection; current IP address; routing table; selected port information (22, 23, 80, 8080, 136, 139, 445, 3389); and system DNS information. | This detects whether the current network connection presents security risks. |
System information | OS name, OS version, kernel version, and ROM version. | This detects system-level security risks such as jailbreak/root or other system vulnerabilities. |
Biometric authentication results | Gesture password (stored locally only, not uploaded); results of the system fingerprint recognition. Please note that fingerprint recognition only invokes the device’s system recognition interface and obtains the recognition result — no raw fingerprint data is collected. To enable remote access to the enterprise user’s intranet applications, the Feature will request VPN permission to establish an encrypted channel; this permission is used solely to establish the channel and does not collect any related information about you. | This verifies user identity for secure connection. |
Clipboard data | Clipboard data (processed locally on the device only). | This scans clipboard information locally during paste operations to provide quick text input. |
Account credentials | User account, name (or nickname), password, mobile number, and email. These items serve as credentials for logging in and using the service, and may be provided by the enterprise administrator. | This verifies user identity and enables login to the Feature. |
Third-party account information | When using a third-party product (such as WeCom, WeChat, Feishu, or DingTalk) to log in to the Feature via Single Sign-On, the third-party product provides the enterprise user with the following: name / nickname, account, mobile number, and email (subject to what the third-party product publicly discloses and provides). | This enables SSO login through third-party products configured by the enterprise user. |
Network gateway data | Proxy Mode (Global Proxy): device network information (e.g., NIC address, IP address, routing information, PID and process name of applications accessing the network). Proxy Mode (Browser Proxy): device network information (e.g., NIC address, IP address, system proxy settings, PID and process name of applications accessing the network). Proxy Mode (WFP Proxy): device network information (e.g., NIC address, IP address, PID and process name of applications accessing the network). Account credentials (Token / Secret); identity identifiers (account / UID); network identifiers (IP / MAC); location information (GeoIP / country); access behaviour (resource / URL / domain / port); endpoint hardware identifiers (host_id / GUID). | This provides zero-trust network access, identity authentication, traffic encryption, access authorisation and behavioural auditing for access to enterprise business resources in accordance with customer instructions and policies. |
Data category | Details | Purpose |
Endpoint / software information | Endpoint name, MAC address, SN (serial number), network IP, client version, endpoint model, CPU, motherboard, motherboard serial number, memory, primary hard drive, graphics card, network adapter, monitor, sound card, SN (serial number), MAC address, and hardware manufacturer. | This supports device binding, management and unbinding based on device information and permissions granted during use of the Feature. |
Software Information | List of installed software, software information (version and developer), and software registry information. | This checks whether specific software is installed, provides uninstallation information and displays software version information. |
Login Information | Login user, hostname, device type, IP address, operating system, last login time, last logout time. The third-party product will provide the enterprise user with your name (or nickname), account, mobile number, and email registered with that third-party product (subject to what the third-party product publicly discloses and provides). | This verifies user identity and enables account login or SSO login configured by the enterprise user. |
Virus Scanning and Removal Data | List of currently running software and hard disk files. | This detects malicious programmes and device vulnerabilities, and supports virus removal and vulnerability remediation. |
Real-time Protection | Employee Account, User Name, User Directory, Device Name, Device ID, Device Group, Device IP, MAC Address, Risk Name, Detection Time, Attack Time, Command Line, Action Result. | This provides real-time endpoint protection against threats from downloads, chat file transfers and USB drives, with enterprise-configured controls for system protection, social engineering defence, lateral movement prevention, document recovery and endpoint deception. |
Endpoint / software information | Endpoint information: endpoint name, MAC address, SN (serial number), network IP, client version, endpoint model, CPU, motherboard, memory capacity, primary hard drive, graphics card, network adapter, monitor, sound card, OS name, OS build number, and system architecture. Software information: list of installed software, software details (name, version, runtime), currently running processes, device OS version, IP address, service information, local port information, and disk information. | This verifies whether the device complies with compliance detection policies configured by the enterprise user and alerts on associated risks. |
Environment information | Device environment, network environment, and application environment information. | This supports local client diagnostics. |
Device network information | Device network information (NIC address, IP address, routing information, and the PID and process name of applications accessing the network). | This modifies device proxy configuration, proxies browser network traffic and forwards traffic according to enterprise user policy configuration. |
Device network information | Device network information (NIC address, IP address, system proxy settings, and the PID and process name of applications accessing the network). | This forwards network traffic according to enterprise user policy configuration. |
Apakah halaman ini membantu?
Anda juga dapat Menghubungi Penjualan atau Mengirimkan Tiket untuk meminta bantuan.
masukan