Security and trust

Your data stays in your tenant. Every action is written down.

SocGenie is hosted on Microsoft Azure in the UK and reads each Microsoft 365 tenant through delegated, least-privilege consent. Agents investigate and propose. A person approves any change. This page says what we do to protect your data, and what we do not do.

01

Your Microsoft tenant

Microsoft 365, Entra ID, Intune, Defender and Sentinel. Your data lives here and stays here.

  • Delegated, least-privilege Microsoft consent
  • Nothing to install
  • Consent visible and revocable in Entra ID
02

SocGenie, hosted in the UK

Microsoft Azure, United Kingdom. Agents assess the tenant, investigate incidents and propose what to do.

  • Secrets encrypted at rest with AES-256-GCM
  • Every request scoped to one organisation
  • Every agent action written to the audit trail
03

Your approval channel

Slack, Microsoft Teams or the SocGenie portal. A person reads the evidence and decides.

  • Nothing changes without a person saying yes
  • Approved actions run through Microsoft Graph
  • The decision joins the audit trail

Nothing changes in your tenant without a human yes.

Controls

What protects your data.

Plain descriptions of the controls in place, in the order they matter to you.

UK hostingMicrosoft Azure, United Kingdom

SocGenie runs on Microsoft Azure in the UK. The platform, its storage and its processing are hosted there.

Delegated, least-privilege consentMicrosoft Graph app consent

Customer data stays in the customer's tenant. SocGenie reads it where it lives, through the Microsoft permissions you grant and nothing more. Nothing is installed in the tenant.

Secrets encrypted at restAES-256-GCM

Any credential or token SocGenie has to hold is encrypted at rest. API keys are stored as hashes, so a key cannot be read back out of the platform.

Short-lived sessionswith revocation

Sessions expire on their own and can be revoked at any time, so a lost laptop or a leaver does not keep a door open.

Hardened application surfaceContent Security Policy, signed webhooks

The portal runs under a strict Content Security Policy. Inbound webhooks are accepted only when their signature verifies.

Per-organisation scopingon every request

Every request is checked against the organisation it belongs to. One customer's data is never visible to another, and a partner sees only the tenants delegated to it.

Audit trail

Every action is written down.

Every agent action, every tool call and every approval goes into the audit trail. You can replay any investigation step by step and see what the agent read, what it proposed, who approved it and when.

  • Every agent action and tool call, in order
  • Every approval, with who decided and when
  • Replay any investigation from the first step
  • No hidden reasoning: if it is not in the trail, it did not happen
What the trail records · one investigationExample
step 1readsign-in history, device compliance, mailbox rules
step 2intelsource address checked against threat intelligence
step 3attacktechnique mapped to MITRE ATT&CK
step 4proposalrevoke sessions, remove the forwarding rule
step 5approvala person decides in Slack, Microsoft Teams or the portal
step 6executedthrough Microsoft Graph, after approval
step 7recordedevery step above, who approved it and when
Read-only work needs no approvalAnything that changes a tenant does

Commitments

Three things we do not do.

01

Train models on your data.

Customer data is never used to train models. It is read to assess and investigate the tenant it belongs to, and for nothing else.

02

Change a tenant on our own.

Agents read, correlate and propose. A person approves in Slack, Microsoft Teams or the portal before anything changes, and the decision is written to the audit trail.

03

Ask for more access than the work needs.

SocGenie connects with delegated, least-privilege Microsoft consent. You can see the permissions it holds in Entra ID and revoke them at any time.

Accreditations

Working towards accreditation.

The standards Reddome is working towards and aligns to. Nothing here is claimed as held until the certificate is issued. Ask for the security pack for the current status and the detail behind each one.

ISO/IEC 27001
ISO/IEC 27001:2022Information security managementStage 1 audit complete · stage 2 underway
AICPA SOC 2
SOC 2AICPA Trust Services CriteriaIn progress
Cyber Essentials Plus
Cyber Essentials PlusUK government-backed schemeIn progress
UK GDPR
UK GDPRData protectionOur obligation under UK law
National Cyber Security Centre
NCSC Cyber Assessment FrameworkAlignmentAlignment in progress
CSA STAR
CSA STARCloud Security AllianceLevel 1 self-assessment in progress
Email trust@socgenie.io for the security pack. Found a vulnerability? Read our vulnerability disclosure policy.

Free scanner coming soon

See it on your own tenant first.

Connect a Microsoft 365 tenant with Microsoft consent, read the permissions it asks for, and get a posture report in your inbox.