Security & trust

Your data, governed to enterprise standard

TenantIQ is built for IT and security teams that need auditability, EU hosting, and compliance evidence — not just dashboards.

Encryption

Connections are encrypted with TLS (1.2 or higher) and data at rest is encrypted on Azure (AES-256). Personal data is additionally encrypted per field with AES-256-GCM, using a dedicated key for each tenant that is protected by Azure Key Vault.

Agentless & scoped access

No endpoint agents or proxies are deployed. TenantIQ connects through Microsoft Graph application permissions that your administrator grants once and can revoke at any time. The Reporting edition is read-only; write permissions exist only in the Automation edition, where remediation is explicitly enabled.

Hosted in the EU

The platform runs exclusively in EU regions of Microsoft Azure. One exception, stated plainly: AI-assisted features send selected data to an AI provider based in the USA (Anthropic) — details under data handling below.

Compliance

Framework coverage

How TenantIQ maps to the regulatory frameworks your organisation is accountable to.

FrameworkWhat it coversHow TenantIQ helps
NIS2Network and information security obligations for critical infrastructure operatorsContinuous risk monitoring, incident-relevant asset inventory, and governance evidence export
ISO 27001Information security management system (ISMS) controls and risk treatmentControl evidence for access management (A.9), asset inventory (A.8), and supplier security (A.15)
BSI IT-GrundschutzGerman federal baseline security controls for IT systemsMapping of M365 configuration posture to relevant Grundschutz building blocks (SYS, APP, ORP)
DSGVO / GDPRLawful processing, data minimisation, and rights fulfilment for EU personal dataData access visibility across M365, automated offboarding to support erasure and portability

Data handling & sub-processors

TenantIQ applies data minimisation: it analyses configuration, identity, device and sharing metadata from your Microsoft 365 tenant, not the content of your emails, files or chats. The points below state exactly what can be accessed, what is read, what is stored and what goes to AI services. A current list of sub-processors is available on request. Processing agreements (DPA / AVV) can be executed under standard terms or your organisation's template.

What TenantIQ can access
The Reporting edition connects with Microsoft Graph application permissions that are all read permissions — none of them can change your tenant. They include Mail.Read and Files.Read.All, which apply tenant-wide and would technically allow content to be read. No permissions for Teams chats or channel messages are requested.
What is actually read
Configuration, identity, device and sharing metadata. For files that is the name, location, owner, last-modified date, and the sharing links and permissions — never the file content. Email-security findings come from Microsoft Defender alerts: mailboxes are not opened and no email content is read.
What is stored
Findings and inventories, for example which file is shared with whom, are stored on Azure in EU regions. Personal data is encrypted per field, with a dedicated key per tenant.
AI-assisted features
Some features (explanations, risk analyses, report narratives) are generated with the AI provider Anthropic (USA). For these, selected configuration, identity and device data is transmitted, such as key figures, policy definitions or, in a risk analysis, user names — never email, file or chat content. Anthropic is on our sub-processor list.
NIS2ISO 27001BSIDSGVO

Frameworks supported; certifications in progress.

Talk to security