Skip to main content

Security

Built for people who ask the hard questions.

Whether IT signs off on it or you approve it yourself, Presify is built to the standard a security review expects: read-only, tenant-isolated, encrypted, and audited.

Read-only, minimal scope

Presify reads Microsoft Teams presence plus the user and group directory information it needs to label and scope users. It never accesses message content, chats, calls, files, or calendars.

Tenant isolation

Every record is scoped to your Microsoft tenant and enforced at the database layer. Cross-tenant access is a hard boundary, tested on every change.

Encryption

Data is encrypted in transit and at rest. Access tokens are encrypted with managed keys and never written to logs.

Least-privilege access

Microsoft Graph access is granted by a one-time admin consent and limited to the permissions Presify actually uses. Internal access is least-privilege and MFA-enforced.

Audit logging

Every state-changing action is recorded to an append-only audit log naming the actor, the action, and the target, including admin actions.

Microsoft-native, no agents

Presify runs on Microsoft Graph with admin consent. There are no endpoint agents to install and nothing running inside your network.

Privacy is part of the design.

The same discipline that protects your data also limits what we collect in the first place.

Data minimization

Presence status and basic directory information, nothing else. Every permission and its purpose is listed publicly in the documentation.

Retention you control

History is bounded by your plan and trimmed automatically. Per-user and workspace-wide deletion are built in, with legal hold for the records you must keep.

An audit trail you can read

Every administrative action lands in an append-only audit log you can review and export, including anything our support staff does in your workspace.

Honest analytics posture

Anomaly flags show their math, exports carry a written notice that presence is evidence for a conversation, and the browser Global Privacy Control signal is honored on this site.

Resilience and transparency.

The operational controls a security review asks about.

Data residency

Your workspace data is stored and processed in US-based AWS regions. People with an EEA, UK, Switzerland, or Canada work location are excluded from monitoring by design.

Incident & breach response

Documented incident-response and breach-notification runbooks, with customer breach notification within 72 hours, so a security event follows a rehearsed path rather than an improvised one.

Sub-processor transparency

Every sub-processor is named with its purpose and location, published in the Privacy Policy and kept current as the list changes.

Backups & recovery

Encrypted, automated database backups with point-in-time recovery, so your history survives an operational failure.

Running a procurement or insurance review? The security packet puts the data flow, permissions, sub-processors, encryption, access, logging, backups, retention, and incident response on one printable page.

Read the security packet