Security architecture

Your data never leaves Microsoft’s cloud.

PIE runs entirely inside Microsoft Azure — the same infrastructure your organisation already trusts. No third-party servers. No external databases. No unknown data paths.

The four questions security teams ask first

Short answers, so your reviewer can get to a decision without sending us a questionnaire.

“Where does our data live?”

Inside Microsoft Azure, end to end. Compute, storage, identity, document processing and secrets are all Azure services. Nothing is handed to a third-party platform.

“Who at AI Cloud Partners can see our SOWs?”

No one. Your statements of work, and the intellectual property inside them, are not available to our staff.

“How do our people sign in?”

With the Microsoft credentials they already have. PIE authenticates through Microsoft Entra ID, so your conditional access policies, MFA and security groups apply automatically.

“What happens when we leave?”

You have thirty days from cancellation to export your data. After that it is deleted from our systems.

The architecture, service by service

Every component PIE runs on is a first-party Microsoft Azure service. Your IT team already knows how to assess every one of them.

Microsoft Entra ID

Multi-tenant sign-in. Your existing conditional access policies, MFA and security groups apply automatically — there is no separate password for your team to manage, and no account for you to deprovision twice.

Azure Cosmos DB

Enterprise NoSQL storage with automatic failover, encrypted at rest with Azure-managed keys. Your data sits in Microsoft’s cloud, not in a database we rent somewhere else.

Azure AI Document Intelligence

Statement-of-work parsing happens inside Azure’s own document service. Your documents are never sent to a third-party processing pipeline.

Azure AI Foundry

Private model deployments inside the Azure boundary, with enterprise data isolation. Nothing is sent to a public endpoint, and nothing you upload is used to train anyone’s model.

Azure Key Vault

Secrets, certificates and keys are held in managed hardware security modules. No credentials in code. No secrets in configuration files.

Azure App Services

Production runs on Azure platform services, with built-in DDoS protection, network isolation and automatic patching.

Identity and access

PIE does not run its own identity system. It uses yours.

Your tenant sets the rules

Sign-in is through Microsoft Entra ID, so conditional access, multi-factor authentication and security group membership are enforced by your policies, not ours. Your administrators manage PIE access from the same Entra admin centre they use for everything else.

Roles, least privilege, audit trail

Inside PIE, access is controlled by three roles — Org Admin, Member and Viewer. Platform administrators work under least privilege, data access is audit logged, and platform health and security are monitored with Azure Application Insights.

How your data is handled

The short version. The Privacy Policy is the full text, and this page does not say anything it does not.

Encryption

In transit, TLS 1.2 or higher. At rest, Azure-managed encryption keys.

What PIE reads

With your authorisation: your Partner Center customer engagement and association data, and your Partner Admin Link associations. Plus usage data inside PIE — features accessed, actions taken, and IP address at city or region level.

What happens at the end

On cancellation you have thirty days to export everything. After that we reserve the right to delete all customer data from our systems.

What we do not do

The commitments that are easiest to check, and the ones most partner tools will not make.

  • We do not host any part of PIE outside Microsoft Azure.
  • We do not use third-party servers or external databases.
  • We do not sell your data, and we do not share it with other partners.
  • Our staff do not access your statements of work or the intellectual property in them.
  • We do not require a configuration change in your customers’ tenants.

Compliance posture, stated plainly

What PIE inherits from Azure

PIE runs on Microsoft Azure services, and inherits the security controls and compliance programme of those services. Microsoft publishes the certifications and audit reports that cover them — including SOC 2 and ISO 27001 — through the Microsoft Trust Center.

What we do not claim

Those certifications are Microsoft’s, for Microsoft’s services. We do not present them as our own, and we do not claim an independent SOC 2 or ISO 27001 certification for AI Cloud Partners. If your review needs a specific attestation, tell us which one and we will tell you straight where we stand.

Still have questions?

Bring them to a thirty-minute call. If we cannot answer something, we will say so.