Privacy by design

Your tenant's data never leaves your tenant in a form anyone can read.

lisa was built by Microsoft 365 engineers who would not deploy a tool that hoards customer identities. Pseudonymisation happens in-memory, raw data is never stored, and offboarding cryptographically erases everything. Here is exactly how it works.

No PII in the platform database

Every user, group, and entity is represented by a one-way pseudonymous token. A full copy of lisa's database reveals signal states, counts, and opaque tokens — no names, emails, or identifiers that link back to a person.

Raw data never persists

Microsoft Graph responses exist only in the scanner's memory. PII is replaced with pseudo-IDs before anything leaves the scan engine; the raw data is discarded and never written to disk or logs.

No agent in your tenant

lisa installs nothing in your environment. The only footprint is a read-only Enterprise Application you can revoke at any time — the lowest possible attack surface.

Privacy by design, end to end

How lisa scans your Microsoft 365 tenant without ever storing personal data.

CUSTOMER MICROSOFT 365 TENANTLISA PLATFORM · ISOLATED AZURE ENVIRONMENTAdmin Consentconsent-callbackActivate Scan Engineenable-scannerGenerate DEK + KEKget-scan-keyInitialise Mapper TableRegister Tenantsave-tenant-profile
Microsoft 365
Customer Tenant
Enterprise Application
Read-only Graph API permissions
Key Management
DEK · KEK · pseudonymisation secrets
Scan Engine
13 scanners · 150 signals · 6 domains
Encryption Store
Encrypted pseudo-ID mapping
Platform Backend
Findings database · edge functions
AI Finding Engine
Powered by Claude
DATA SECURITY GUARANTEE
🔑Key Management+🗄Encryption Store+📊Platform Backend→ 🔓 data readable
All three must be simultaneously compromised
Setup
Tenant Onboarding

The customer grants Admin Consent through the standard Microsoft flow. This creates an Enterprise Application in their tenant — the only footprint lisa ever has in a customer environment. No software is installed and no write access is granted. The Scan Engine generates a unique DEK and KEK, held exclusively in Key Management, initialises an encrypted pseudo-ID mapper in the Encryption Store, and registers the tenant in the Platform Backend. All three stores start empty and are individually meaningless.

See it on your own tenant — read-only.

Authorize read-only access and review the prioritized report with your team. No agents, no stored PII, no commercial conversation until you have seen what we found.