Polaris Governance

Security & trust

The strongest security story is where your data isn’t.

Polaris governs some of the most sensitive parts of your Microsoft 365 estate, so how we handle access matters. Our honest answer is architectural: the product runs inside your tenant and your Azure subscription. Your sharing graph never lands in a vendor cloud, because there isn’t one to land in.

Read this page as our posture, not a badge wall. Polaris is an early-stage, pre-revenue company. We will not dress that up with certifications we don’t hold, staff we don’t employ, or tools we don’t run. Everything below is either true today or clearly marked as roadmap. If a control isn’t listed, assume we don’t claim it — and ask us.

Last reviewed: July 2026. Security questions and disclosures: info@polarisgovernance.com.

The architectural difference

Your data stays in your tenant.

Not a policy promise — a deployment model. This is the real answer to “where does our data go?”

In your subscription

Polaris deploys into your own Azure subscription and Microsoft 365 tenant. The warehouse of permissions, agents, and labels is built where your data already lives — under your own Entra ID, Conditional Access, and Purview controls.

No data exfiltration

We don’t pull your tenant’s content into a multi-tenant lake to analyse it. There is no shared store of your sharing graph on our side, so there is no cross-customer commingling to worry about.

You keep the keys

Because it runs in your tenant, your existing identity, network, and monitoring controls apply to Polaris the same way they apply to anything else you run — no new trust boundary to extend to a vendor.

Permissions

Least-privilege, and enforcement you have to opt into.

Polaris reads your estate through Microsoft’s own APIs, with the narrowest permissions that do the job — and the permissions that could change anything are separate, optional, and off until you choose to arm them.

01
Read scopes are minimised and documented Access is via Microsoft Graph and the platform admin APIs with the least privilege each feature needs — no blanket grants, and we can tell you exactly what each one is for.
02
Write scopes are separated and optional The permissions remediation needs are distinct from read, and are only added if and when you decide to arm a remediation campaign.
03
Enforcement is default-off and consent-gated Nothing writes to your tenant until an admin explicitly arms a campaign, previews it in dry-run, and confirms. Every action captures its undo — we validated remove → verify-gone → undo → verify-restored before trusting it.
04
Identity is Microsoft’s, not ours Authentication runs through Microsoft Entra ID. Polaris does not operate a separate credential store for your users.

The platform underneath is Microsoft’s. Because Polaris runs on Microsoft 365 and Azure, the infrastructure it sits on carries Microsoft’s own certifications (SOC 2, ISO 27001, FedRAMP, and others). That is Microsoft’s assurance about their platform — we mention it for completeness, and we’re careful not to present it as if it were ours.

Compliance roadmap

Where we are, and where we’re honestly headed.

Today

What’s true now

An architecture that keeps your data in your tenant, least-privilege and consent-gated permissions, and reversible enforcement we’ve validated on our own estate first.

Roadmap

SOC 2 — when it’s real to pursue

SOC 2 is on our roadmap, targeted around our first paying customers — the point at which a formal audit is both meaningful and warranted. We are not currently engaged in an audit, and we won’t claim an in-progress report we don’t have. When it’s underway, we’ll say so here with dates we can stand behind.

What we don’t claim

The honest disclaimers, stated plainly.

Vendor security pages often imply more than a young company has. Here’s what we are not asserting, so you don’t have to guess:

No current SOC 2, ISO 27001, or third-party audit report.

These are on the roadmap, not in hand. Ask and we’ll tell you exactly where things stand.

No penetration-test report or CAIQ package to hand out yet.

We’d rather say that than circulate a document that doesn’t exist.

No claims about a security team, background checks, or a 24/7 SOC.

We’re a small operation. Our security story is the architecture and the least-privilege model above, not a staffed operations centre.

No signed HIPAA BAA or regulated-data guarantees today.

If your use involves regulated data, tell us and we’ll be straight about what we can and can’t commit to at this stage.

Responsible disclosure

Found something? Tell us.

If you believe you’ve found a security issue in Polaris or on polarisgovernance.com, email us with steps to reproduce and the impact. We’ll acknowledge it, work it in good faith, and we won’t pursue researchers acting in good faith who avoid privacy violations, data destruction, and service disruption. One human reads every report.

Security & privacy contact: info@polarisgovernance.com