Security
Built for enterprise review — the same questions your CISO will ask, answered on every product.
Security overview
UV Apps are designed to run in your Microsoft 365 tenant. Most applications have no Azure backend and store no customer data outside SharePoint or Entra ID.
Data processing
Where Graph is used, data is processed in the browser or in your tenant. Phase 4+ SaaS modules will publish a DPA and subprocessors in the Trust Center.
Data residency
In-tenant apps inherit your Microsoft 365 residency. No additional UV Apps region is required for Phase 1 products.
Permissions
Every product lists Microsoft Graph scopes individually, with a business reason. We prefer delegated permissions.
Microsoft Graph access
Consent is explicit. Application permissions appear only when an admin-approved job requires them (for example provisioning).
Azure services
Optional. Flagged on the product page when a backend is required.
Encryption
In transit: TLS. At rest: Microsoft 365 platform encryption for tenant-stored content.
Authentication
Microsoft Entra ID. No separate UV Apps identity store for in-tenant apps.
Telemetry
Off by default. If enabled later, it will be documented per product.
Vulnerability reporting
Email security@unifiedvision.eu. We acknowledge reports and coordinate disclosure.