Privacy by design
Your tenant's data never leaves your tenant in a form anyone can read.
lisa was built by Microsoft 365 engineers who would not deploy a tool that hoards customer identities. Pseudonymisation happens in-memory, raw data is never stored, and offboarding cryptographically erases everything. Here is exactly how it works.
No PII in the platform database
Every user, group, and entity is represented by a one-way pseudonymous token. A full copy of lisa's database reveals signal states, counts, and opaque tokens — no names, emails, or identifiers that link back to a person.
Raw data never persists
Microsoft Graph responses exist only in the scanner's memory. PII is replaced with pseudo-IDs before anything leaves the scan engine; the raw data is discarded and never written to disk or logs.
No agent in your tenant
lisa installs nothing in your environment. The only footprint is a read-only Enterprise Application you can revoke at any time — the lowest possible attack surface.
Privacy by design, end to end
How lisa scans your Microsoft 365 tenant without ever storing personal data.
The customer grants Admin Consent through the standard Microsoft flow. This creates an Enterprise Application in their tenant — the only footprint lisa ever has in a customer environment. No software is installed and no write access is granted. The Scan Engine generates a unique DEK and KEK, held exclusively in Key Management, initialises an encrypted pseudo-ID mapper in the Encryption Store, and registers the tenant in the Platform Backend. All three stores start empty and are individually meaningless.
See it on your own tenant — read-only.
Authorize read-only access and review the prioritized report with your team. No agents, no stored PII, no commercial conversation until you have seen what we found.