Recursyv
Security

Building to Microsoft's Copilot security and governance standard — and why it matters even if you use Claude

Microsoft defines a detailed security and governance standard for Copilot Studio, its agents and its connectors: identity and least privilege through Entra ID, data loss prevention and Advanced Connector Policies, data residency, auditing through Application Insights and Purview, action safety, and lifecycle governance.

We build Recursyv AI connectors to align with that standard for a simple reason: it is the most thorough model an enterprise security reviewer is likely to hold us against, and many of our prospects are mandated to use Copilot.

What alignment means in practice

  • Identity — connectors authenticate via OAuth 2.1 through the customer’s own identity provider and request least-privilege, per-tool scopes. There is no parallel credential path.
  • Action safety — read by default; write scopes kept separate; no delete or irreversible action is ever exposed as a tool.
  • Data handling — zero customer business data at rest; processing pinned to a named Azure region per customer.
  • Auditing — a per-call record (tool, tenant, user, timestamp, sanitised parameters, result) exportable to the customer’s SIEM.

Why it matters for non-Copilot customers

The controls above are properties of the connector, not the assistant. A Claude or ChatGPT customer gets exactly the same permission model, the same audit trail and the same zero-data-at-rest architecture. Aligning to Microsoft’s standard simply means we have designed to the most demanding published benchmark — and can show a security team the mapping.

Talk to the people who wrote this.

Recursyv's engineers are a call away.