Skip to content

Everscope security

Know exactly what Everscope can access—and what it cannot do.

Security starts with a narrow product boundary: metadata-driven analysis, tenant-scoped authorisation and no automatic changes to the Microsoft estate.

Implemented boundaries

Controls you can evaluate before onboarding.

These statements describe the current product behaviour. Everscope does not claim certifications it has not completed.

Metadata, not business rows

Everscope inventories object metadata, definitions and operational signals. It does not retrieve or store underlying business-data rows from semantic models.

Tenant-scoped access

Application queries, roles, exports and API keys are resolved inside the connected tenant context. A Microsoft sign-in alone does not grant governance write access.

Encrypted credentials

Stored Microsoft credential material is encrypted at rest. Session cookies are HTTP-only, secure in production and protected with same-site controls.

Human-controlled action

Rules create recommendations and evidence. Everscope does not automatically modify or delete Microsoft Fabric or Power BI content.

Permission minimisation

Customers can begin with delegated user scope. Tenant-wide Scanner API access remains optional and requires explicit administrator consent.

EU operation

The production runtime and primary data services are configured in EU regions. Retention and deletion controls are documented in the Privacy Notice.

Data flow in plain language

A connection produces governance evidence, not a copy of your data warehouse.

  1. Everscope requests the Microsoft metadata permissions selected by the user.
  2. Versioned rules evaluate inventory and available definitions.
  3. Findings, ownership and decisions remain isolated to the organisation.
  4. Users export or act on evidence explicitly; remediation is never automatic.

Current assurance position

Honest evidence over badge collecting.

Everscope documents permissions, subprocessors, retention, deletion and incident contacts. Formal enterprise assurance and contract requirements can be discussed before an Enterprise agreement.