Products assessed
A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.
Certifications
What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
- — Vendor claimed
- — Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Org-level report; Product Terms mark SSAE 18 SOC 2 Type II as Yes for Office 365 Services, defined to include Microsoft 365 Copilot. The Service Trust Portal catalogue lists a current Azure + Dynamics 365 + Online Services SOC 2 Type II report (period 1 Apr 2025 to 31 Mar 2026) and Microsoft 365 SOC 2 Type 2 reports, with bridge letters covering the period since.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · Microsoft Service Trust Portal (SOC report catalogue) · checked Aug 27, 2026
Org-level report; the claim is SOC 1 Type II marked Yes for Office 365 Services in the Product Terms. The Service Trust Portal catalogue lists a current Azure + Dynamics 365 + Online Services SOC 1 Type II report (period 1 Apr 2025 to 31 Mar 2026) and Microsoft 365 SOC 1 Type 2 reports with a July 2026 bridge letter.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · Microsoft Service Trust Portal (SOC report catalogue) · checked Aug 27, 2026
Certificate face states the scope: the ISMS supporting Microsoft Azure, Dynamics 365, and other Online Services deployed in Azure Public and Government Cloud, per statement of applicability version 2026.01. Resolves the scope_unclear on this org-level report; the vault also holds the separate Microsoft 365 ISO/IEC 27001:2022 certificate (valid 2024-2027) covering the M365 scope.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · Schellman certificate of registration held in the TrustyCyber vault (Microsoft Service Trust Portal) · checked Aug 27, 2026
Valid until Jun 16, 2029
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Aug 28, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · CSA STAR Registry · checked Aug 28, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Aug 28, 2026
How to read this
This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. This record reflects the evidence available on Aug 28, 2026.
