D365 Audit

Security & Privacy

The strongest guarantee: we never touch your live environment

D365 Audit never connects to your Dataverse tenant. No app registration, no API permissions, no service account, no OAuth consent. You upload a file you already exported yourself. You decide yourself what is analyzed - nothing more, nothing less. There is no live-access attack surface to secure, because there is no live access.

How does the analysis technically work?

The uploaded file is parsed and evaluated by deterministic, rule-based logic running locally on the server - no AI is involved in the analysis itself. Solutions follow a clearly defined structure with little to no room for interpretation, which is exactly the kind of task that doesn't benefit from AI: fixed rules deliver a more precise, reproducible result. Your solution content is never sent to OpenAI, Anthropic, or any other external API service.

What is stored?

  • The uploaded ZIP and the solution files extracted from it are deleted immediately after the analysis - they only exist on the server for the duration of processing (typically seconds).
  • The generated reports (PDF/Word/Excel) and aggregated metrics (number of fields/entities etc.) remain stored for a limited time (default: 7 days) so the report can be downloaded after payment - after that, automatic deletion occurs.
  • Only with explicit consent (a checkbox at upload is enabled by default): an anonymized log entry with technical anomalies (e.g. new XML structure patterns, warnings, frequency of triggered rules) is stored for product improvement. Data such as the solution name, publisher name, or the content of fields, entities or descriptions is never recorded.
  • Payment data is processed exclusively by Stripe (Stripe Checkout), never by us.
  • Contact form requests (name, email, message) are forwarded by email to consulting@d365audit.de.

Where is this site hosted?

EU (Frankfurt region). No transfer outside the EU.

Which encryption is used?

Data in transit is always encrypted via HTTPS/TLS.

Which cookies are used?

We use Google Analytics (GA4) with IP anonymization and Google Ads to measure advertising conversions - but only after you explicitly agree in the cookie banner. If you decline or ignore the banner, no Google script is loaded and no analytics cookie is set. One strictly necessary cookie stores your choice. Marketing cookies are not used.

How does D365 Audit differ from the Power Platform Solution Checker?

Together they give the full picture – we do not replace the Solution Checker, we answer a different question. The checker asks: “Is the code clean?” We ask: “Can a new team take over, maintain and migrate this solution?”

What the Solution Checker does
Static code analysis against Microsoft best-practice rules: JavaScript and web resource patterns (deprecated APIs, eval, unsafe DOM access), plug-in registrations, Power Fx expressions and canvas app accessibility. It does that well, and there is no substitute for it.
What we add
Structure, documentation and governance – everything the checker does not look at: documentation coverage per component type, prefix consistency across teams, dependency exposure to third-party solutions, the full list of import prerequisites including version numbers, outbound data flows (service endpoints, custom connectors, dataflows), and typical ALM mistakes such as environment values shipped inside the solution that end up in production on import.
Practical differences
The Solution Checker only runs on unmanaged solutions and only inside your environment, so you need access to it. Our report is produced from the exported ZIP alone: you can assess someone else's solution before taking it over, or review a managed solution. The result is not a violation log but a handover and decision document as PDF, Word and Excel.

In short: the Solution Checker reviews the quality of the code. We assess the state of the solution as a whole – and deliver the document you can decide on.

Which products are supported?

Apps built on Microsoft Dataverse (Sales, Customer Service, Field Service, similar Customer Engagement apps, and Power Apps). Business Central is not covered, because it uses a fundamentally different extension model (AL/.app) with no comparable solution export.

Does D365 Audit work with cloud or on-premises?

The format of the solution export (customizations.xml) is the same regardless of the hosting model. Our assessment works in both cases.

What permissions do you need on our tenant?

None. See above. We never connect to your environment; we only work with the solution package containing your customisations. Your sensitive customer data can never reach us.

What happens with data from the reference programme?

The reference programme is entirely voluntary: you receive the report free of charge and in return allow us to name your company as a reference. It plays no part in the analysis itself.

What we store: company name and address, the name of your contact person, the company website, the business email address you provide, and the logo you upload. Nothing else. Legal basis is your consent (Art. 6(1)(a) GDPR).

What is published: only your company logo, linked to your website. Never your name, your email address or anything from your analysis.

Why a business email address: the address must be on the domain of the company website you provide, and we send a confirmation link to it. This is how we check that a reference is genuinely issued by the company itself.

Withdrawing consent: you can withdraw at any time with a single click on the link in the confirmation email, without giving reasons and without contacting us. We then remove the logo from the website. The report already delivered stays with you.

How long we keep the data: as long as the reference is active. After a withdrawal the logo file is deleted immediately; the remaining entry is anonymised after 90 days, so that we can still prove that and when a withdrawal happened. A registration that is never confirmed is deleted completely after 30 days, including the uploaded logo.

The logo is not publicly retrievable until it is published on the site; until then it is stored internally only. Data is deleted after withdrawal.