Security and Privacy

Security and Privacy

How Contract Risk Scanner for Microsoft 365 protects your data.


The short version

  • ✅ Runs entirely inside your Microsoft 365 tenant
  • No external services are contacted
  • No data egress - your contracts never leave your environment
  • No persistent storage by us - outputs live in your OneDrive/SharePoint
  • No AI model training on your data
  • ✅ Uses your existing M365 security and compliance controls

Architecture

Contract Risk Scanner for Microsoft 365 is a Copilot agent built on the Microsoft 365 Agents Toolkit. It:

  • Is installed in your tenant via the Microsoft Marketplace
  • Runs as part of Microsoft 365 Copilot
  • Has no backend service operated by VIDEOTEC LLC
  • Makes no API calls outside the M365 boundary

📖 Read more: How It Works


Data handling

What happens to your contract data

Stage Where data lives Who has access
Upload Your Copilot session You and M365 Copilot
Analysis Microsoft 365 Copilot service Microsoft’s standard Copilot boundary
Output Your chat / your OneDrive / your SharePoint You
Persistence None by us Wherever you choose to save outputs

What we never do

  • ❌ Send your contracts to VIDEOTEC LLC servers
  • ❌ Copy data to external storage
  • ❌ Use your data to train AI models
  • ❌ Share your data with third parties
  • ❌ Retain your data after your session ends

Microsoft 365 Copilot data boundary

Your data is governed by Microsoft 365 Copilot’s data protection commitments:

  • 🔐 Data stays within your tenant boundary
  • 🔐 Encrypted in transit and at rest
  • 🔐 Not used to train Microsoft’s foundation models
  • 🔐 Subject to your existing M365 compliance posture

Read Microsoft’s Copilot privacy documentation:


Compliance

What we inherit

Because Contract Risk Scanner for Microsoft 365 runs inside Microsoft 365, it inherits Microsoft 365’s compliance posture, including:

  • ISO 27001
  • SOC 2 Type II
  • HIPAA (where applicable in your M365 plan)
  • GDPR
  • FedRAMP (where applicable in your M365 plan)

What you control

  • Your data classification policies
  • Your DLP rules
  • Your audit logging configuration
  • Your retention policies

These all apply to Contract Risk Scanner for Microsoft 365 outputs the same way they apply to any other Copilot interaction.


Permissions

Contract Risk Scanner for Microsoft 365 requests the minimum necessary permissions:

  • Access to chat messages and uploaded files within Copilot
  • No directory read
  • No mail access
  • No external API access

Your admin can review these permissions in the Microsoft 365 admin center.


With or without a Copilot license

With Copilot license

The agent can access documents in your OneDrive/SharePoint if you reference them. All access is governed by your existing M365 permissions.

Without Copilot license

You upload files directly into the chat. Files exist in the session only.


Audit and traceability

Every scan output includes:

  • Agent version
  • Scan timestamp
  • Scanning user (when integrated with M365 identity)
  • Custom risk register version (if one was uploaded)

This metadata is included in CSV and JSON exports for audit trails.


Subprocessors

VIDEOTEC LLC does not use any third-party subprocessors for Contract Risk Scanner for Microsoft 365.

The agent definition is hosted in the Microsoft Marketplace. All processing happens within Microsoft 365 Copilot, using whichever AI models your tenant administrator has enabled.

Note: If your tenant has third-party models enabled (e.g., Claude via Azure AI), Copilot may route processing through those models, which could involve infrastructure outside your Microsoft 365 tenant boundary. This is controlled entirely by your tenant administrators — not by Contract Risk Scanner. The agent respects all tenant-level model and data controls.


Data residency

Your data resides wherever your Microsoft 365 tenant is hosted. Contract Risk Scanner for Microsoft 365 adds no additional data residency considerations.


Reporting a security concern

If you discover a security vulnerability or have a concern:

✉️ Email support@videotec.io

We commit to responding within 2 business days.