Security & trust
Your data, governed to enterprise standard
TenantIQ is built for IT and security teams that need auditability, EU hosting, and compliance evidence — not just dashboards.
Encryption
Connections are encrypted with TLS (1.2 or higher) and data at rest is encrypted on Azure (AES-256). Personal data is additionally encrypted per field with AES-256-GCM, using a dedicated key for each tenant that is protected by Azure Key Vault.
Agentless & scoped access
No endpoint agents or proxies are deployed. TenantIQ connects through Microsoft Graph application permissions that your administrator grants once and can revoke at any time. The Reporting edition is read-only; write permissions exist only in the Automation edition, where remediation is explicitly enabled.
Hosted in the EU
The platform runs exclusively in EU regions of Microsoft Azure. One exception, stated plainly: AI-assisted features send selected data to an AI provider based in the USA (Anthropic) — details under data handling below.
Compliance
Framework coverage
How TenantIQ maps to the regulatory frameworks your organisation is accountable to.
| Framework | What it covers | How TenantIQ helps |
|---|---|---|
| NIS2 | Network and information security obligations for critical infrastructure operators | Continuous risk monitoring, incident-relevant asset inventory, and governance evidence export |
| ISO 27001 | Information security management system (ISMS) controls and risk treatment | Control evidence for access management (A.9), asset inventory (A.8), and supplier security (A.15) |
| BSI IT-Grundschutz | German federal baseline security controls for IT systems | Mapping of M365 configuration posture to relevant Grundschutz building blocks (SYS, APP, ORP) |
| DSGVO / GDPR | Lawful processing, data minimisation, and rights fulfilment for EU personal data | Data access visibility across M365, automated offboarding to support erasure and portability |
Data handling & sub-processors
TenantIQ applies data minimisation: it analyses configuration, identity, device and sharing metadata from your Microsoft 365 tenant, not the content of your emails, files or chats. The points below state exactly what can be accessed, what is read, what is stored and what goes to AI services. A current list of sub-processors is available on request. Processing agreements (DPA / AVV) can be executed under standard terms or your organisation's template.
- What TenantIQ can access
- The Reporting edition connects with Microsoft Graph application permissions that are all read permissions — none of them can change your tenant. They include Mail.Read and Files.Read.All, which apply tenant-wide and would technically allow content to be read. No permissions for Teams chats or channel messages are requested.
- What is actually read
- Configuration, identity, device and sharing metadata. For files that is the name, location, owner, last-modified date, and the sharing links and permissions — never the file content. Email-security findings come from Microsoft Defender alerts: mailboxes are not opened and no email content is read.
- What is stored
- Findings and inventories, for example which file is shared with whom, are stored on Azure in EU regions. Personal data is encrypted per field, with a dedicated key per tenant.
- AI-assisted features
- Some features (explanations, risk analyses, report narratives) are generated with the AI provider Anthropic (USA). For these, selected configuration, identity and device data is transmitted, such as key figures, policy definitions or, in a risk analysis, user names — never email, file or chat content. Anthropic is on our sub-processor list.