Trust & security

The safest thing you'll connect to a tenant.

Sabiki Security·Security overview·Agentless · human-approved change

AIRM is designed to be the lowest-risk integration in a client tenant: agentless, human-approved, and reversible in one click. Nothing is installed, no business content is read, and nothing changes unless a human explicitly acts. Here is exactly how it works.

How AIRM connects

What AIRM can access, and what it can't

AIRM reads identity and permission metadata only: users, applications, service principals, OAuth grants, role assignments, and sign-in and audit metadata. It does not read mailboxes, files, chats, or any business content. It cannot create, modify or delete anything in the tenant unless you explicitly choose to act on a finding.

The permissions we request

PermissionWhyAccess
Directory.Read.AllList users, apps and service principals (the non-human identities)READ
Application.Read.AllSee app registrations, agents and their granted scopesREAD
AuditLog.Read.AllSpot stale or unused credentialsREAD

What we store

AIRM stores the identity inventory and risk findings needed to produce the report and the Sabiki NHI Risk Score. It does not store your emails, files or business content.

Revoke access at any time

Go to the Microsoft Entra admin centre → Enterprise applications → Sabiki AIRM → revoke. Access ends immediately. You stay in full control.

Hosting & data residency

AIRM and the customer portal run on Microsoft Azure, in the Southeast Asia region (Singapore). The identity inventory and the risk findings are stored in MongoDB Atlas, a managed database service, running on Azure in the same Singapore region. Your tenant data stays in Singapore.

Azure holds ISO/IEC 27001, ISO 27018 and SOC 1, SOC 2 Type 2 and SOC 3. MongoDB Atlas holds ISO/IEC 27001:2022, ISO 27017, ISO 27018, SOC 2 and CSA STAR. Both publish their reports in their own trust centres, and both are named on our sub-processor page. These are our providers' certifications, not ours. Sabiki's own SOC 2 audit is underway, and we will not claim a certification before it exists.

Certifications & attestations

Sabiki AIRM is a Microsoft Verified Publisher, which means Microsoft has confirmed the identity of the publisher behind the application. That is a statement about who we are, not a certification of the product, and we will not present it as one.

A SOC 2 audit is presently underway. This page will be updated when the report is issued. We will not claim a certification before it exists, and we will not ask you to take that on trust in the meantime.

What we can point at today is architecture rather than paperwork: AIRM is agentless, makes no change without human approval, stores identity findings rather than your content, and can be revoked from the Entra admin centre at any time, ending access immediately.

Sub-processors

A current list of sub-processors and the purpose of each is maintained and provided on request, and to every customer before a tenant is connected.

Security questions before you connect a tenant?

Talk to us directly, or run the free Sabiki NHI Risk Score on any Microsoft 365 tenant and see exactly what AIRM does.

Free AI Readiness Score →
← Back to home