Security

Built for enterprise review — the same questions your CISO will ask, answered on every product.

Security overview

UV Apps are designed to run in your Microsoft 365 tenant. Most applications have no Azure backend and store no customer data outside SharePoint or Entra ID.

Data processing

Where Graph is used, data is processed in the browser or in your tenant. Phase 4+ SaaS modules will publish a DPA and subprocessors in the Trust Center.

Data residency

In-tenant apps inherit your Microsoft 365 residency. No additional UV Apps region is required for Phase 1 products.

Permissions

Every product lists Microsoft Graph scopes individually, with a business reason. We prefer delegated permissions.

Microsoft Graph access

Consent is explicit. Application permissions appear only when an admin-approved job requires them (for example provisioning).

Azure services

Optional. Flagged on the product page when a backend is required.

Encryption

In transit: TLS. At rest: Microsoft 365 platform encryption for tenant-stored content.

Authentication

Microsoft Entra ID. No separate UV Apps identity store for in-tenant apps.

Telemetry

Off by default. If enabled later, it will be documented per product.

Vulnerability reporting

Email security@unifiedvision.eu. We acknowledge reports and coordinate disclosure.