Trust & security
How OneView handles your organisation's data
OneView is built by Tecor Partners for corporate teams whose data lives in Microsoft 365. This page explains, in plain language, what we access, where it goes, how it is protected and how you get rid of it. We describe the controls we have actually built. We do not hold third-party certifications and we do not claim compliance with any framework.
What happens to your data
- 1
You sign in with Microsoft
Microsoft authenticates you and shows the exact permissions below. OneView receives tokens — never your password.
- 2
Recent items are copied into your workspace
The last few days of mail, calendar and (optionally) Teams messages you can already see are stored in a row-level-secured workspace scoped to your organisation and your account.
- 3
A briefing is produced
The engine summarises what changed, what needs attention, who is waiting on you, decisions, meetings to prepare for and commitments — with a citation for every claim.
- 4
Content expires
Items older than your organisation's retention period are purged automatically. Disconnecting deletes your content and wipes your tokens straight away.
Security controls
Each of these is implemented in the product and documented in the security architecture.
Entra ID single sign-on only
OneView has no passwords to store or leak. Sign-in is an OpenID Connect authorization-code flow with PKCE against your organisation's Microsoft Entra ID, so your MFA and Conditional Access policies apply unchanged.
Delegated, read-only permissions
Every Microsoft Graph permission is delegated (acts as you, limited to what you can already see) and read-only. OneView never requests organisation-wide application permissions.
Isolation enforced by the database
Each organisation and each user is isolated with PostgreSQL row-level security. Queries that forget a filter return nothing rather than someone else's data — this is tested, not assumed.
Encrypted tokens
Microsoft access and refresh tokens are stored as AES-256-GCM envelopes with per-secret data keys wrapped by a versioned master key. Keys can be rotated without disconnecting anyone.
AI under your organisation's policy
By default, briefings are produced in-workspace with no external AI call. An administrator can allow specific external providers and require redaction of e-mail addresses, phone numbers and similar identifiers before anything leaves the workspace.
Retrieved content is treated as untrusted
Mail and chat text is delimited, stripped of instruction-like phrases and schema-validated before and after any model call. The AI has no tools: it cannot send mail, call APIs or act on your behalf.
Audit trail you can see
Sign-ins, syncs, briefings, searches, policy changes and deletions are logged. You can review your own activity in the app; tenant administrators see the whole organisation.
Retention and deletion you control
Content is kept for a configurable number of days (30 by default) and then purged. You can disconnect and delete everything yourself; the deletion runs immediately and is recorded.
Hardened sessions
Server-side sessions with HttpOnly, Secure, SameSite cookies, idle and absolute timeouts, CSRF checks on every change, a devices view with sign-out-everywhere, and re-authentication for sensitive actions.
Cloudflare in front
Production deployments run behind Cloudflare with WAF, rate limiting on sign-in and API routes, bot protection on public forms (never on the Microsoft sign-in itself) and optional Cloudflare Access on administrator routes.
Every permission OneView can ask for
Sign-in requests only the identity, mail and calendar permissions. Teams access is a separate opt-in step. Reading channel messages needs approval from your Microsoft 365 administrator, and an organisation may require administrator approval for all of these.
Signing in
Sign you in
openidRead-onlyLets you sign in with your work account.
Basic profile
profileRead-onlyYour name and job title, to personalise your briefing.
E-mail address
emailRead-onlyYour work e-mail address, used as your account identifier.
Stay connected
offline_accessRead-onlyKeeps your connection alive so OneView can refresh in the background. You can disconnect at any time.
Read your profile
User.ReadRead-onlyRead your own user profile (name, title, e-mail).
Outlook mail
Read your mail
Mail.ReadRead-onlyRead messages in your own mailbox. OneView cannot send, move or delete mail.
Calendar
Read your calendar
Calendars.ReadRead-onlyRead events in your own calendar. OneView cannot create or change events.
Microsoft Teams
Read your Teams chats
Chat.ReadRead-onlyRead 1:1 and group chats you are part of. OneView cannot post messages.
Read channel messages
ChannelMessage.Read.AllRead-only Admin approvalRead messages in channels of teams you belong to. Requires approval from your Microsoft 365 administrator.
What we are honest about
- OneView is not SOC 2, ISO 27001 or otherwise certified. Our enterprise-readiness notes describe what is in place and what is still planned.
- A copy of recent content is stored in OneView's workspace for the retention period — it does not stay solely inside Microsoft 365.
- If your administrator enables an external AI provider, redacted content is sent to that provider under their terms. The default is off.
- Security is a process. Found something? Tell us and we will fix it and record it.