Sync 365 Infrastructure Security | Azure North Europe

Infrastructure Security Overview

Sync 365 is designed with security, privacy and least-privilege access at the centre of its infrastructure and operating practices. This overview explains where the platform is hosted, how access is controlled, and which Microsoft services and permissions support its core features.

Hosting and data location

Sync 365 is hosted entirely in Microsoft Azure in the North Europe region.

Our backend uses a serverless-first architecture, with Azure Functions handling most automated processing and Azure Database for MySQL providing managed data storage. Our controls are aligned with applicable Microsoft Azure security guidance, including:

Security and access controls

  • Restricted infrastructure access: Access to the Azure environment is limited to authorised company directors and personnel who require it.
  • Controlled production changes: Development and deployment changes are managed through Azure DevOps and require approval before release to production.
  • Protected data: Sensitive information is protected using appropriate security controls, and passwords are salted and hashed where applicable.
  • Data minimisation: We aim to collect and retain only the information required to provide and operate Sync 365.
  • Least-privilege integrations: Access to Microsoft customer environments is limited to the permissions required for enabled features.

SOC 2 Type II

Sync 365 is currently working toward SOC 2 Type II attestation. This programme includes the continued development, documentation and independent assessment of the controls that support the security and reliability of our service.

We will update this article as the programme progresses. This statement should not be interpreted as confirmation that Sync 365 has already completed or received SOC 2 Type II attestation.

Microsoft Partner Center access

Sync 365 uses the Microsoft Partner Center API to retrieve the information required for core licensing and billing automation, including:

  • Customer records
  • Partner information
  • Tenant licence information
  • Subscription information for direct CSP partners

Advanced Microsoft 365 features

Some optional features require access to additional information in a customer tenant. Depending on the features enabled, Sync 365 may retrieve:

  • Microsoft Entra ID: Users and groups
  • Exchange Online: Mailbox information

This information supports features such as filtering licences by Microsoft Entra ID attributes, adding usernames to invoices, synchronising contacts to a PSA, and calculating custom licence or mailbox counts.

GDAP and permission accountability

Customer-tenant access uses the available Granular Delegated Admin Privileges (GDAP) relationship and the permissions granted by the partner. Activity remains associated with the authorised identity used to grant partner consent.

For more information, see Microsoft’s introduction to GDAP.