Security and privacy
Security, privacy and data processing
This page is technical and plain on purpose. What we actually do, what we hold, and what we are not.
Zero standing rights — for people.
The platform has them, and that is the entire point: the right moves from twelve people who can do anything at any time, to one service that can only do what an approved order asks for, with a full trail on every action.
Permissions on this page means one thing only: the Microsoft Graph consent the platform holds. The matrix of who may request what and who approves it is a different mechanism, and it is called access rules.
Access rules
Who may request, who approves, what is logged.
Delegation is expressed as rules, not as roles handed out by hand. A service desk agent may reset a password in three companies but order a new hire in one. Every rule states its approver, and every execution lands in the same record as the request.
How we connect to your tenant
Entra Logic connects as an Entra ID application approved by a global administrator in your organization. We ask for the least access the features you actually use require, and we use delegated permissions where possible. We never ask for passwords and we store no user credentials. Consent can be withdrawn in the Entra portal at any time, and access ends immediately.
Where data is stored and processed
The service runs inside the EEA. Customer data is stored in Microsoft Azure, Norway East (Oslo). UK customers can have UK South on request. We do not mirror your directory: we store identifiers, role and access assignments, and the action log needed to deliver the features. Data is encrypted in transit (TLS 1.2 or later) and at rest, and environments are logically separated per customer.
Data processing agreement and GDPR
You are the controller for the personal data in your own tenant; Entra Logic is the processor. The DPA is part of the customer agreement and is published below — no form, no sales call. It covers purpose, categories of data, sub-processors, security measures, breach notification and deletion or return of data on termination. We notify you without undue delay, and at the latest within 24 hours, of a personal data breach, so you can meet your own 72-hour deadline.
Access control, logging and continuity
Sign-in to our own systems requires multi-factor authentication. Access is granted by role, reviewed periodically and removed on role change or departure. Administrative actions in the service are logged with who, what, when and on what basis, and the log can be exported by you. Backups run daily and are restore-tested. We have documented incident handling, and vulnerabilities can be reported to us directly for coordinated handling.
How we work with least privilege ourselves
Nobody at Entra Logic holds standing administrator rights in customer environments. Access is granted for a specific purpose and a specific window, approved by you, and logged. When the task is finished, the access falls away automatically.
Sub-processors
One, and you already use it.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd. (Azure) | Hosting, storage and backup | Norway East (Oslo), UK South on request |
Changes to the sub-processor list are notified in writing at least 30 days before they take effect.
Documents, no form
Everything a security review asks for, published.
Certification status: not certified yet.
We are not SOC 2 or ISO 27001 certified today. We work to the ISO 27001 principles for access control, logging, change management and supplier follow-up, but we will not call it certification until an external auditor has said so.
We also do not do access certification campaigns, attestation or segregation-of-duties analysis. Those are real disciplines, and the product does not cover them.
On regulation: Norway's digital security act took effect on 1 October 2025 and implements the original NIS directive. NIS2 has not been adopted in Norway — adoption is expected during 2026 — so nothing on this site claims that NIS2 requires anything of you today.
How to remove us again
Entra portal → Enterprise applications → Entra Logic → Properties → Delete.
Access ends immediately. Data we have read is deleted within 30 days, or right away if you ask.
We put this here so you know it before you start, not so you have to go looking for it afterwards.