Aristo — Trust, Security & Governance

Everything a security, procurement, or IT reviewer needs, in one place. Aristo is a warm companion, not a watchtower — and every claim here is one we can defend. We state plainly what is in place today and what is in progress, never a certification we don't hold.

Security posture

What's in place today, what's in progress, and what's available on request — the procurement-ready picture.
🕊️ Our honesty rule: Aristo is young. We will not claim SOC 2 "certified" until it is. "In progress" means exactly that — with our current posture and roadmap shown so you can assess risk today.

Data handling — in place today

No training on your data✅ In place
Your content is used only to produce your result, then dropped. Never used to train any model, never leaves the compliant AI boundary. AI calls are stateless and per-request.
Consent on every action✅ In place
Aristo never sends, books, or changes anything on its own. Every action is an explicit button-press by the user (on-behalf-of).
Least-privilege, on-behalf-of✅ In place
The do-it-with-me skills run AS each user (OBO) with minimal scopes. Aristo holds no standing tenant-wide mailbox access.
Tenant data isolation✅ In place
Each customer's state is partitioned per-tenant (Cosmos partition key) and queried only by that tenant id.
Encryption in transit & at rest✅ In place
TLS everywhere; data at rest encrypted by Azure-managed keys. Customer-managed keys planned for the top tier.
Aggregate-only — five or more people✅ In place
Manager/admin views are aggregate — shown only for five or more people, never who-did-what. We keep only minimal per-user operational state (to message you + count your own wins) — no leader-facing activity trail. Opt-out + deletion honored. The single exception is named recognition — and it is yours, not your organization’s: if your org turns it on, only the people who personally say yes are ever shown by name. Everyone else stays in the blend, and a yes can be taken back in one word, any time.
SIEM / audit-log export✅ In place
The aggregate governance ledger exports to your SIEM (Sentinel/Splunk) as JSON or CSV — /api/audit/export.

Certifications & enterprise controls — in progress

SOC 2 Type II / ISO 27001🟡 In progress
Not yet certified (we're early). Controls are being implemented; an independent penetration test + CAIQ/SIG-Lite are planned. Current posture available now.
SSO (SAML/OIDC) + SCIM🟡 In progress
Sign-in to the admin console is via Microsoft Entra today; full SAML/OIDC + SCIM provisioning is on the near-term roadmap.
Data residency / EU boundary🟡 In progress
Hosted in a single named Azure region — Azure Central US — with a geo-redundant store and 4-hourly backups. EU Data Boundary support and tenant-selectable residency are planned for regulated/EU buyers.
GDPR — DPA, DPIA, DSAR🟡 In progress
A Data Processing Agreement is available; a DPIA template, lawful-basis statement, and right-to-erasure (DSAR) flow are in progress.
Accessibility — WCAG 2.2 AA / VPAT🟡 In progress
Built mobile-first and high-contrast; a formal WCAG 2.2 AA conformance audit + VPAT are planned.
BCP/DR + uptime SLA🟡 In progress
Running on Azure Container Apps with managed availability; a formal RTO/RPO + uptime SLA + incident-response commitment are being documented.

On request

Sub-processor list📋 On request
Microsoft Azure (hosting, Graph) + the AI model providers (OpenAI/Anthropic via compliant endpoints). Full list + DPAs on request.
Your mandated AI vendor📋 On request
If your policy names a specific AI vendor or model, your tenant can be pinned to it — every Aristo call then routes only there, with no silent fallback to another vendor. Arranged with your team during onboarding.
Graph permission blast-radius📋 On request
The exact scopes Aristo requests, why, and a frank "what a compromise could expose" statement — provided for your security review.

The Graph scopes Aristo uses (and why)

Least-privilege, each explained at consent. Delegated scopes act only as the signed-in user; app-only scopes are read-only and, for mail, hard-scoped by an Exchange policy.
As the user (OBO, delegated): User.Read (who you are) · Mail.Read + Mail.Send (draft & send YOUR reply, only on your press) · Calendars.Read (prep your next meeting).

App-only (admin-consented, scoped): Reports.Read.All (who has Copilot but isn't using it — the cold cohort) · Mail.Read restricted by an Application Access Policy to only the mailboxes in scope · ServiceMessage.Read.All (Message Center, for the tenant Capability Radar) · CopilotPackages.Read.All (optional — your tenant's Copilot agent inventory, requires Microsoft Agent 365 licensing). Each is the minimum for its job.

What each permission does — and what you miss without it

Every permission Aristo can request, in plain words: what it reads, what it powers in the Report, and exactly what you lose if you don’t grant it. The three marked optional widen the picture — Aristo works without them.
PermissionWhat it readsWhat it powers in the ReportWhat you miss without it
Reports.Read.AllAggregate Copilot usage — whole teams of five or more, never an individual.Q2 the idle-seat money; Q1/Q3 the activation numbers and the cold cohort a nudge can warm.No idle-$ to recover, no activation %, no “who’s cold” to help — the money and usage questions go dark.
Organization.Read.AllYour licence / SKU inventory — bought vs assigned per SKU.Q2 shelf seats (bought − assigned) and the renewal right-sizing defense.No bought-vs-assigned truth — shelf seats and the renewal-defense numbers can’t be shown.
User.Read.AllDirectory departments — for grouping only, never per-person activity.Q3 the k-anonymous team rows (department × SKU).No team breakdown — the estate can only be shown whole-org, never by team.
SecurityEvents.Read.All
optional — Aristo works without it
Your Microsoft Secure Score.Q1 the security-posture pillar of the Frontier Score (25%).The security pillar is dropped and the remaining pillars re-weighted — the score still computes, just without posture.
Delegated (User.Read · Mail.Read/Send · Calendars.Read)Acts AS the signed-in user, only on their press — the Teams / Office do-it-with-me context.The in-Teams warm saves and draft-and-send-your-own-reply, on-behalf-of.No do-it-with-me help in Teams or Office — Aristo can measure, but can’t warmly act with a person.
ServiceMessage.Read.All
optional — Aristo works without it
Your tenant’s own Message Center posts (Copilot-relevant).Q6 shows the one change that reached YOUR tenant, with the how-to already written.Without it you get Microsoft’s public roadmap instead — the generic feed, not what actually landed for you.
CopilotPackages.Read.All
optional — Aristo works without it
Your tenant’s Copilot agent catalog (requires Microsoft Agent 365 licensing).The Q3 register lists every agent in your tenant, whoever built it.Without it only Aristo-forged agents appear — external agents stay off the register.

How Aristo reaches your people

Three delivery channels, and only three. Every report surface says "Aristo comes to you" — this is that claim, itemised, so a reviewer can check each one rather than take it. Aristo has no channel outside this table.
1 · The Teams app — a bot, in your tenant
A Microsoft Teams app your admin installs. It is where Aristo speaks: a 30-second digest to your named sponsors each Monday, and a card to the leaders a policy names the day a spending traffic light worsens — checked once daily, never continuously. Proactive messages are capped at one per person per day with a cooldown, and one word — "stop" — ends them permanently. Every action inside a card is an explicit button-press by the user.
2 · The declarative agent, in Microsoft 365 Copilot
The same app package registers a Microsoft 365 Copilot declarative agent, Aristo Spark (copilotAgents.declarativeAgents in the Teams app manifest). Microsoft surfaces it automatically in Word, Excel, PowerPoint, Outlook and Copilot Chat once installed — your people ask it where they already are, with no portal to open. Scope, stated plainly: it declares no Graph capabilities and reads no tenant data; its two actions return general Copilot guidance and an explanation of how credits work, and it is instructed never to state an individual's numbers. Your Frontier Score, licence and spend figures live on the reports and in the Teams app — with an optional, separate agent package your own admin can register if you want those numbers inside Copilot chat too.
3 · Exports — what a leader carries out
Each of the three reports leaves as a PowerPoint deck (the Frontier Firm Report in four room-specific versions — board, finance, IT, seller), and the Frontier Firm Report also as a spoken audio brief. Every export is generated on request for a signed-in leader from the same counted composition the page shows, so an exported figure and a live figure can never disagree. Nothing is emailed, published or sent anywhere on Aristo's own initiative — an export exists because a leader pressed a button.
🕊️ Why this section exists: the product's own promise is that nobody has to spend their day inside it — the answer arrives in Teams, in Copilot, or in the deck they are already presenting. A promise like that is only worth making if a reviewer can enumerate every channel it hides behind. That is the whole table.

Governance ledger

Care, not surveillance — the aggregate record of how Aristo behaves, and the lines it will never cross.
Tasks done with explicit consent
Nudges today (under the cap)
Opt-outs honored
People Aristo has met
Sign in to your Aristo workspace (or open the demo) to see live aggregate numbers for a tenant. The guarantees below always apply.
No pressure, ever
At most 1 proactive message per person per day, with a cooldown between them. One word — "stop" — silences Aristo instantly and permanently, no friction.
Every action is consented
Aristo never sends an email, books, or changes anything on its own. It drafts and offers; the user presses the button. Nothing happens without an explicit, in-the-moment yes.
Least privilege
Read-only, scoped permissions. The do-it-with-me drafting runs as each user (on-behalf-of) — Aristo never holds tenant-wide mailbox access, and asks only for what a given action needs.
No training on your data
Your content is processed transiently to produce a result, then dropped. It is never used to train models and never leaves the compliant boundary of the AI service.
Aggregate only — by design
Manager and admin views are aggregate — shown only for five or more people, showing health and never "who did what." The only per-person data we keep is the minimal operational state needed to reach you in Teams and count your own wins — never a leader-facing activity trail — and it is opt-out and deletable. The single exception is named recognition — and it is yours, not your organization’s: if your org turns it on, only the people who personally say yes are ever shown by name. Everyone else stays in the blend, and a yes can be taken back in one word, any time.

What Aristo deliberately does not keep

The Aristo covenant →Where your answers go →Privacy policy →Terms of use →Support →

Questions for security review? A full DPA, sub-processor list, and SOC 2 status are available on request — hello@phoenixhalo.com. A PhoenixHalo product.