Trust & transparency
Microsoft data access
What Fronterio reads, writes, and deliberately never touches in your Microsoft tenant. One page, eight integrations, no marketing fluff. Suitable for security questionnaires.
Last updated against the live source code on the dev branch.
Read the full technical appendixEight integrations, all opt-in, all independently revocable
Fronterio touches Microsoft in eight distinct ways. Every one of them is opt-in: nothing Microsoft-related happens until your tenant admin grants explicit consent, or you sign in with Microsoft. Every connection can be revoked from your tenant at any time, and Fronterio's database deletes the related data on disconnect.
At a glance
| Integration | What it's for | Who consents | Tenant scope |
|---|---|---|---|
| Microsoft sign-in | Logging in with Microsoft | The signing-in user | Your account only |
| Copilot adoption tracker | Department-level Copilot usage dashboard | Tenant admin (delegated) | Tenant-wide reports |
| SharePoint intranet sync | Mirror governance data into your intranet | Tenant admin (app-only) | One SharePoint site |
| Microsoft Teams agent | Fronterio bot inside Teams | Admin sideloads, users install | Bot conversations only |
| Copilot Studio integration | Discover & govern Copilot Studio agents | Tenant admin (app-only) | Power Platform environments |
| M365 Copilot Chat | Fronterio in Copilot Chat | Inherits Teams agent | Same as Teams |
| Microsoft Commercial Marketplace | Buy Fronterio via Microsoft | Buying admin | Subscription metadata only |
| Azure AI Foundry deployment | Deploy governed agents into Azure | Customer Azure admin | One resource group |
Data residency & sub-processors
Microsoft services are your own tenant in every case above. They are not Fronterio sub-processors — Fronterio does not control the Microsoft data plane and cannot transfer data out of your tenant beyond the read scopes you explicitly granted. Fronterio's own infrastructure runs on Supabase (Frankfurt, EU), Vercel (EU regions), and Anthropic for AI calls (US, under SCCs + the EU-US DPF). No customer Microsoft data is ever sent to Anthropic. Marketplace customers route AI calls through Azure AI Foundry (Sweden Central) instead.
View the full sub-processors listYour controls
Disconnect any integration
Settings → Integrations on the Fronterio side, or revoke admin consent in Microsoft Entra at any time. Either action stops the next sync and clears the relevant credentials.
Right to access (DSAR)
Export everything Fronterio knows about you as a JSON bundle from Settings → Privacy.
Right to deletion
Delete your account or your entire organisation from Settings. Audit log entries are written before deletion so the record survives.
Audit log
Every PII read against Microsoft-derived data is logged for Article 32 evidence.
DPA
Data Processing Agreement available at /dpa with SCCs, EU-US DPF, and zero data retention addendum on AI calls.
Questions or a security review request?
Email dpo@fronterio.com. Security reviewers can request a live walk-through of the source files referenced in the technical appendix.
dpo@fronterio.com