Security & data handling
The access model
- Read-only, provably. The permissions we request cannot write to your tenant, and the execution engine enforces a Get-only allowlist with a per-command audit trail. Directory roles we ask you to assign (Global Reader) are read-only by definition.
- No credentials of yours, ever. Access works through Microsoft's app-consent model: your admin grants our application consent; Microsoft issues us tokens. Revoke the enterprise app in Entra and access stops instantly — enforced by Microsoft, not by us.
- Configuration, not content. We read settings and policies. We cannot read mail, files, chats or user content — the permission list makes this verifiable.
What we store, and where
- Your organisation name and domain, configuration values, and their change history.
- Stored in Azure Database for PostgreSQL, UK South, encrypted at rest and in transit, with tenant isolation enforced in the application layer and by PostgreSQL row-level security.
- Secrets (our certificate, connection strings) live in Azure Key Vault behind managed identities.
- Automated backups: 7 days.
Revocation and deletion
Delete the serv365 Watchdog enterprise application in Entra at any time — collection stops immediately and the tenant is automatically marked revoked on our side. To have stored configuration data erased, email contact@serv365.ai from an admin address of the tenant; purges are completed within 7 days and confirmed.
Subprocessors
Microsoft Azure (hosting, database, Key Vault, email — UK/EU regions). No analytics or advertising third parties; the public site sets no tracking cookies.
Roadmap
Single sign-on with your own Entra accounts for the dashboard, formal certification (SOC 2), and a sovereign deployment option (the entire platform running inside your own Azure subscription) are on the committed roadmap for regulated customers. Questions: contact@serv365.ai.