Security & Compliance
DC Workflow is built on Microsoft Azure and runs entirely within your Microsoft 365 environment. Documents and review data are stored in your own SharePoint and never transmitted to or stored by DC Workflow infrastructure.
Every organisation's data is siloed to its own Microsoft 365 tenant. There is no shared storage. No DC Workflow employee can access your documents.
Every API request is authenticated against Azure AD. No service-level shared credentials. All access flows through your existing Conditional Access and MFA policies.
Document uploads, reviewer assignments, approvals, and transmittal generation are all logged with user identity, timestamp, and IP address.
Deployed through Teams Admin Center. IT controls who has access, which SharePoint sites are in scope, and which Graph API permissions are granted, without end-user intervention.
DC Workflow requests the minimum Graph API permissions it needs to work. All permissions require explicit administrator consent before any user can authorise the application.
DC Workflow does not request permissions to read email inboxes, access calendars, manage users, or access Teams messages. The full permission list is declared in the app manifest and reviewed during Teams Admin Center approval.
Found a security vulnerability? Please report it to security@dcworkflow.com before any public disclosure. We acknowledge all credible reports within 24 hours and work to remediate verified vulnerabilities as a priority. We do not pursue legal action against good-faith security researchers.
Contact enterprise@dcworkflow.com to request the full security documentation pack: the DPA, pen test summary, VSQ responses, and Azure AD integration guide.