Metadata, not business rows
Everscope inventories object metadata, definitions and operational signals. It does not retrieve or store underlying business-data rows from semantic models.
Everscope security
Security starts with a narrow product boundary: metadata-driven analysis, tenant-scoped authorisation and no automatic changes to the Microsoft estate.
Implemented boundaries
These statements describe the current product behaviour. Everscope does not claim certifications it has not completed.
Everscope inventories object metadata, definitions and operational signals. It does not retrieve or store underlying business-data rows from semantic models.
Application queries, roles, exports and API keys are resolved inside the connected tenant context. A Microsoft sign-in alone does not grant governance write access.
Stored Microsoft credential material is encrypted at rest. Session cookies are HTTP-only, secure in production and protected with same-site controls.
Rules create recommendations and evidence. Everscope does not automatically modify or delete Microsoft Fabric or Power BI content.
Customers can begin with delegated user scope. Tenant-wide Scanner API access remains optional and requires explicit administrator consent.
The production runtime and primary data services are configured in EU regions. Retention and deletion controls are documented in the Privacy Notice.
Data flow in plain language
Current assurance position
Everscope documents permissions, subprocessors, retention, deletion and incident contacts. Formal enterprise assurance and contract requirements can be discussed before an Enterprise agreement.