Sync 365 is designed with security, privacy and least-privilege access at the centre of its infrastructure and operating practices. This overview explains where the platform is hosted, how access is controlled, and which Microsoft services and permissions support its core features.
Sync 365 is hosted entirely in Microsoft Azure in the North Europe region.
Our backend uses a serverless-first architecture, with Azure Functions handling most automated processing and Azure Database for MySQL providing managed data storage. Our controls are aligned with applicable Microsoft Azure security guidance, including:
Sync 365 is currently working toward SOC 2 Type II attestation. This programme includes the continued development, documentation and independent assessment of the controls that support the security and reliability of our service.
We will update this article as the programme progresses. This statement should not be interpreted as confirmation that Sync 365 has already completed or received SOC 2 Type II attestation.
Sync 365 uses the Microsoft Partner Center API to retrieve the information required for core licensing and billing automation, including:
Some optional features require access to additional information in a customer tenant. Depending on the features enabled, Sync 365 may retrieve:
This information supports features such as filtering licences by Microsoft Entra ID attributes, adding usernames to invoices, synchronising contacts to a PSA, and calculating custom licence or mailbox counts.
Customer-tenant access uses the available Granular Delegated Admin Privileges (GDAP) relationship and the permissions granted by the partner. Activity remains associated with the authorised identity used to grant partner consent.
For more information, see Microsoft’s introduction to GDAP.