Privacy by design

Your tenant's data never leaves your tenant in a form anyone can read.

lisa was built by Microsoft 365 engineers who would not deploy a tool that hoards customer identities. Pseudonymisation happens in-memory, raw data is never stored, and offboarding cryptographically erases everything. Here is exactly how it works.

No PII in the platform database

Every user, group, and entity is represented by a one-way pseudonymous token. A full copy of lisa's database reveals signal states, counts, and opaque tokens — no names, emails, or identifiers that link back to a person.

Raw data never persists

Microsoft Graph responses exist only in the scanner's memory. PII is replaced with pseudo-IDs before anything leaves the scan engine; the raw data is discarded and never written to disk or logs.

No agent in your tenant

lisa installs nothing in your environment. The only footprint is a read-only Enterprise Application you can revoke at any time — the lowest possible attack surface.

Your data stays in Switzerland

All scan data lives in Swiss data centres: the platform database runs in Zürich and the scan engine, key vault, and pseudonym store run in Azure Switzerland North. Your Microsoft 365 data itself never leaves your own tenant — lisa reads it there and stores only pseudonymised results.

Privacy by design, end to end

How lisa scans your Microsoft 365 tenant without ever storing personal data.

CUSTOMER MICROSOFT 365 TENANTLISA PLATFORM · ISOLATED AZURE ENVIRONMENTAdmin Consentconsent-callbackActivate Scan Engineenable-scannerGenerate DEK + KEKget-scan-keyInitialise Mapper TableRegister Tenantsave-tenant-profile
Microsoft 365
Customer Tenant
Enterprise Application
Read-only Graph API permissions
Key Management
DEK · KEK · pseudonymisation secrets
Scan Engine
13 scanners · 150 signals · 6 domains
Encryption Store
Encrypted pseudo-ID mapping
Platform Backend
Findings database · edge functions
AI Finding Engine
Powered by Claude
DATA SECURITY GUARANTEE
🔑Key Management+🗄Encryption Store+📊Platform Backend→ 🔓 data readable
All three must be simultaneously compromised
Setup
Tenant Onboarding

The customer grants Admin Consent through the standard Microsoft flow. This creates an Enterprise Application in their tenant — the only footprint lisa ever has in a customer environment. No software is installed and no write access is granted. The Scan Engine generates a unique DEK and KEK, held exclusively in Key Management, initialises an encrypted pseudo-ID mapper in the Encryption Store, and registers the tenant in the Platform Backend. All three stores start empty and are individually meaningless.

See it on your own tenant — read-only.

Authorize read-only access and review the prioritized report with your team. No agents, no stored PII, no commercial conversation until you have seen what we found.