Security & trust
The strongest security story is where your data isn’t.
Polaris governs some of the most sensitive parts of your Microsoft 365 estate, so how we handle access matters. Our honest answer is architectural: the product runs inside your tenant and your Azure subscription. Your sharing graph never lands in a vendor cloud, because there isn’t one to land in.
Read this page as our posture, not a badge wall. Polaris is an early-stage, pre-revenue company. We will not dress that up with certifications we don’t hold, staff we don’t employ, or tools we don’t run. Everything below is either true today or clearly marked as roadmap. If a control isn’t listed, assume we don’t claim it — and ask us.
Last reviewed: July 2026. Security questions and disclosures: info@polarisgovernance.com.
The architectural difference
Your data stays in your tenant.
Not a policy promise — a deployment model. This is the real answer to “where does our data go?”
In your subscription
Polaris deploys into your own Azure subscription and Microsoft 365 tenant. The warehouse of permissions, agents, and labels is built where your data already lives — under your own Entra ID, Conditional Access, and Purview controls.
No data exfiltration
We don’t pull your tenant’s content into a multi-tenant lake to analyse it. There is no shared store of your sharing graph on our side, so there is no cross-customer commingling to worry about.
You keep the keys
Because it runs in your tenant, your existing identity, network, and monitoring controls apply to Polaris the same way they apply to anything else you run — no new trust boundary to extend to a vendor.
Permissions
Least-privilege, and enforcement you have to opt into.
Polaris reads your estate through Microsoft’s own APIs, with the narrowest permissions that do the job — and the permissions that could change anything are separate, optional, and off until you choose to arm them.
The platform underneath is Microsoft’s. Because Polaris runs on Microsoft 365 and Azure, the infrastructure it sits on carries Microsoft’s own certifications (SOC 2, ISO 27001, FedRAMP, and others). That is Microsoft’s assurance about their platform — we mention it for completeness, and we’re careful not to present it as if it were ours.
Compliance roadmap
Where we are, and where we’re honestly headed.
Today
What’s true now
An architecture that keeps your data in your tenant, least-privilege and consent-gated permissions, and reversible enforcement we’ve validated on our own estate first.
Roadmap
SOC 2 — when it’s real to pursue
SOC 2 is on our roadmap, targeted around our first paying customers — the point at which a formal audit is both meaningful and warranted. We are not currently engaged in an audit, and we won’t claim an in-progress report we don’t have. When it’s underway, we’ll say so here with dates we can stand behind.
What we don’t claim
The honest disclaimers, stated plainly.
Vendor security pages often imply more than a young company has. Here’s what we are not asserting, so you don’t have to guess:
These are on the roadmap, not in hand. Ask and we’ll tell you exactly where things stand.
We’d rather say that than circulate a document that doesn’t exist.
We’re a small operation. Our security story is the architecture and the least-privilege model above, not a staffed operations centre.
If your use involves regulated data, tell us and we’ll be straight about what we can and can’t commit to at this stage.
Responsible disclosure
Found something? Tell us.
If you believe you’ve found a security issue in Polaris or on polarisgovernance.com, email us with steps to reproduce and the impact. We’ll acknowledge it, work it in good faith, and we won’t pursue researchers acting in good faith who avoid privacy violations, data destruction, and service disruption. One human reads every report.
Security & privacy contact: info@polarisgovernance.com