D365 Audit

Security & Privacy

The strongest guarantee: we never touch your live environment

D365 Audit never connects to your Dataverse tenant. No app registration, no API permissions, no service account, no OAuth consent. You upload a file you already exported yourself - nothing more, nothing less. There is no live-access attack surface to secure, because there is no live access.

How does the analysis technically work?

The uploaded file is parsed and evaluated by deterministic, rule-based logic running locally on the server - no AI is involved in the analysis itself. Solutions follow a clearly defined structure with little to no room for interpretation, which is exactly the kind of task that doesn't benefit from AI: fixed rules deliver a more precise, reproducible result. Your solution content is never sent to OpenAI, Anthropic, or any other external API service.

What is stored?

  • The uploaded ZIP and the solution files extracted from it are deleted immediately after the analysis - they only exist on the server for the duration of processing (typically seconds).
  • The generated reports (PDF/Word/Excel) and aggregated metrics (number of fields/entities etc.) remain stored for a limited time (default: 7 days) so the report can be downloaded after payment - after that, automatic deletion occurs.
  • Only with explicit consent (checkbox at upload, checked by default): an anonymized log entry with technical anomalies (e.g. new XML structure patterns, warnings, frequency of triggered rules) for product improvement - never solution name, publisher name, or field/entity/description content.
  • Payment data is processed exclusively by Stripe (Stripe Checkout), never by us.
  • Contact form requests (name, email, message) are forwarded by email to consulting@d365audit.de.

Where is data hosted?

EU (Frankfurt region). No transfer outside the EU.

Which encryption is used?

Data in transit is always encrypted via HTTPS/TLS.

Cookies

No tracking or marketing cookies are currently set. One purely technical cookie remembers that the cookie notice was confirmed.

Technical scope

Supported products
Apps built on Microsoft Dataverse (Sales, Customer Service, Field Service, Power Apps, and similar Customer Engagement apps). Business Central is not covered, because it uses a fundamentally different extension model (AL/.app) with no comparable solution export.
Cloud or on-premises?
The unmanaged solution export format (customizations.xml) is the same regardless of hosting model - the assessment works either way.
What permissions do you need on our tenant?
None. See above - we never connect to your environment.