Security and Privacy
Security and Privacy
How Contract Risk Scanner for Microsoft 365 protects your data.
The short version
- ✅ Runs entirely inside your Microsoft 365 tenant
- ✅ No external services are contacted
- ✅ No data egress - your contracts never leave your environment
- ✅ No persistent storage by us - outputs live in your OneDrive/SharePoint
- ✅ No AI model training on your data
- ✅ Uses your existing M365 security and compliance controls
Architecture
Contract Risk Scanner for Microsoft 365 is a Copilot agent built on the Microsoft 365 Agents Toolkit. It:
- Is installed in your tenant via the Microsoft Marketplace
- Runs as part of Microsoft 365 Copilot
- Has no backend service operated by VIDEOTEC LLC
- Makes no API calls outside the M365 boundary
📖 Read more: How It Works
Data handling
What happens to your contract data
| Stage | Where data lives | Who has access |
|---|---|---|
| Upload | Your Copilot session | You and M365 Copilot |
| Analysis | Microsoft 365 Copilot service | Microsoft’s standard Copilot boundary |
| Output | Your chat / your OneDrive / your SharePoint | You |
| Persistence | None by us | Wherever you choose to save outputs |
What we never do
- ❌ Send your contracts to VIDEOTEC LLC servers
- ❌ Copy data to external storage
- ❌ Use your data to train AI models
- ❌ Share your data with third parties
- ❌ Retain your data after your session ends
Microsoft 365 Copilot data boundary
Your data is governed by Microsoft 365 Copilot’s data protection commitments:
- 🔐 Data stays within your tenant boundary
- 🔐 Encrypted in transit and at rest
- 🔐 Not used to train Microsoft’s foundation models
- 🔐 Subject to your existing M365 compliance posture
Read Microsoft’s Copilot privacy documentation:
Compliance
What we inherit
Because Contract Risk Scanner for Microsoft 365 runs inside Microsoft 365, it inherits Microsoft 365’s compliance posture, including:
- ISO 27001
- SOC 2 Type II
- HIPAA (where applicable in your M365 plan)
- GDPR
- FedRAMP (where applicable in your M365 plan)
What you control
- Your data classification policies
- Your DLP rules
- Your audit logging configuration
- Your retention policies
These all apply to Contract Risk Scanner for Microsoft 365 outputs the same way they apply to any other Copilot interaction.
Permissions
Contract Risk Scanner for Microsoft 365 requests the minimum necessary permissions:
- Access to chat messages and uploaded files within Copilot
- No directory read
- No mail access
- No external API access
Your admin can review these permissions in the Microsoft 365 admin center.
With or without a Copilot license
With Copilot license
The agent can access documents in your OneDrive/SharePoint if you reference them. All access is governed by your existing M365 permissions.
Without Copilot license
You upload files directly into the chat. Files exist in the session only.
Audit and traceability
Every scan output includes:
- Agent version
- Scan timestamp
- Scanning user (when integrated with M365 identity)
- Custom risk register version (if one was uploaded)
This metadata is included in CSV and JSON exports for audit trails.
Subprocessors
VIDEOTEC LLC does not use any third-party subprocessors for Contract Risk Scanner for Microsoft 365.
The agent definition is hosted in the Microsoft Marketplace. All processing happens within Microsoft 365 Copilot, using whichever AI models your tenant administrator has enabled.
Note: If your tenant has third-party models enabled (e.g., Claude via Azure AI), Copilot may route processing through those models, which could involve infrastructure outside your Microsoft 365 tenant boundary. This is controlled entirely by your tenant administrators — not by Contract Risk Scanner. The agent respects all tenant-level model and data controls.
Data residency
Your data resides wherever your Microsoft 365 tenant is hosted. Contract Risk Scanner for Microsoft 365 adds no additional data residency considerations.
Reporting a security concern
If you discover a security vulnerability or have a concern:
✉️ Email support@videotec.io
We commit to responding within 2 business days.
Related reading
- 🧠 How It Works
- 📥 Installation
- ❓ FAQ