Back

Trust & security

How OneView handles your organisation's data

OneView is built by Tecor Partners for corporate teams whose data lives in Microsoft 365. This page explains, in plain language, what we access, where it goes, how it is protected and how you get rid of it. We describe the controls we have actually built. We do not hold third-party certifications and we do not claim compliance with any framework.

What happens to your data

  1. 1

    You sign in with Microsoft

    Microsoft authenticates you and shows the exact permissions below. OneView receives tokens — never your password.

  2. 2

    Recent items are copied into your workspace

    The last few days of mail, calendar and (optionally) Teams messages you can already see are stored in a row-level-secured workspace scoped to your organisation and your account.

  3. 3

    A briefing is produced

    The engine summarises what changed, what needs attention, who is waiting on you, decisions, meetings to prepare for and commitments — with a citation for every claim.

  4. 4

    Content expires

    Items older than your organisation's retention period are purged automatically. Disconnecting deletes your content and wipes your tokens straight away.

Security controls

Each of these is implemented in the product and documented in the security architecture.

Entra ID single sign-on only

OneView has no passwords to store or leak. Sign-in is an OpenID Connect authorization-code flow with PKCE against your organisation's Microsoft Entra ID, so your MFA and Conditional Access policies apply unchanged.

Delegated, read-only permissions

Every Microsoft Graph permission is delegated (acts as you, limited to what you can already see) and read-only. OneView never requests organisation-wide application permissions.

Isolation enforced by the database

Each organisation and each user is isolated with PostgreSQL row-level security. Queries that forget a filter return nothing rather than someone else's data — this is tested, not assumed.

Encrypted tokens

Microsoft access and refresh tokens are stored as AES-256-GCM envelopes with per-secret data keys wrapped by a versioned master key. Keys can be rotated without disconnecting anyone.

AI under your organisation's policy

By default, briefings are produced in-workspace with no external AI call. An administrator can allow specific external providers and require redaction of e-mail addresses, phone numbers and similar identifiers before anything leaves the workspace.

Retrieved content is treated as untrusted

Mail and chat text is delimited, stripped of instruction-like phrases and schema-validated before and after any model call. The AI has no tools: it cannot send mail, call APIs or act on your behalf.

Audit trail you can see

Sign-ins, syncs, briefings, searches, policy changes and deletions are logged. You can review your own activity in the app; tenant administrators see the whole organisation.

Retention and deletion you control

Content is kept for a configurable number of days (30 by default) and then purged. You can disconnect and delete everything yourself; the deletion runs immediately and is recorded.

Hardened sessions

Server-side sessions with HttpOnly, Secure, SameSite cookies, idle and absolute timeouts, CSRF checks on every change, a devices view with sign-out-everywhere, and re-authentication for sensitive actions.

Cloudflare in front

Production deployments run behind Cloudflare with WAF, rate limiting on sign-in and API routes, bot protection on public forms (never on the Microsoft sign-in itself) and optional Cloudflare Access on administrator routes.

Every permission OneView can ask for

Sign-in requests only the identity, mail and calendar permissions. Teams access is a separate opt-in step. Reading channel messages needs approval from your Microsoft 365 administrator, and an organisation may require administrator approval for all of these.

Signing in

  • Sign you in

    openid Read-only

    Lets you sign in with your work account.

  • Basic profile

    profile Read-only

    Your name and job title, to personalise your briefing.

  • E-mail address

    email Read-only

    Your work e-mail address, used as your account identifier.

  • Stay connected

    offline_access Read-only

    Keeps your connection alive so OneView can refresh in the background. You can disconnect at any time.

  • Read your profile

    User.Read Read-only

    Read your own user profile (name, title, e-mail).

Outlook mail

  • Read your mail

    Mail.Read Read-only

    Read messages in your own mailbox. OneView cannot send, move or delete mail.

Calendar

  • Read your calendar

    Calendars.Read Read-only

    Read events in your own calendar. OneView cannot create or change events.

Microsoft Teams

  • Read your Teams chats

    Chat.Read Read-only

    Read 1:1 and group chats you are part of. OneView cannot post messages.

  • Read channel messages

    ChannelMessage.Read.All Read-only Admin approval

    Read messages in channels of teams you belong to. Requires approval from your Microsoft 365 administrator.

What we are honest about

  • OneView is not SOC 2, ISO 27001 or otherwise certified. Our enterprise-readiness notes describe what is in place and what is still planned.
  • A copy of recent content is stored in OneView's workspace for the retention period — it does not stay solely inside Microsoft 365.
  • If your administrator enables an external AI provider, redacted content is sent to that provider under their terms. The default is off.
  • Security is a process. Found something? Tell us and we will fix it and record it.