Evaluate Infralign
Security and data flow
Data moves one way, out of your tenant into an EU region. One hop leaves it. Six questions close a security review.
Data moves one way: out of your Azure tenant, over cost and control-plane APIs, into a warehouse hosted in Microsoft Azure, Italy North (EU). The platform issues no workload or resource-configuration writes to your estate. One chatbot hop leaves that region, and the reference page marks it.
What a security review needs to close
Section titled “What a security review needs to close”Each row names the page that answers it in full. Work down the list and a review closes; nothing below is summarised here, because a summary of a security control is the thing that goes stale first.
| Question | Where it is answered |
|---|---|
| Where is the data hosted, how is each tenant isolated, and what leaves the EU region? | Security and data handling, which also covers encryption, sub-processors, retention, and deletion |
| What does Infralign collect, and what does it never collect? | Data sources |
| What can the Reader role see, and where does its data-plane boundary fall? | Why Reader, and what it cannot see |
| What happens at each step between the nightly pull and a dashboard? | How your data flows, which annotates the diagram step by step |
| How do we stop collection? | Revoking access, which you run yourself |
| Which steps does a person perform rather than the platform? | Available today versus roadmap |