Microsoft 365 Copilot
microsoft.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- Data retention window not stated
- Underlying model providers not named
See Before you sign, with what to ask for ↓
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“For the purposes of data retention and deletion, a Services configuration or custom model that has been inactive may at Microsoft's discretion be treated as an Online Service for which the Customer's subscription has expired.”
Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.
What to ask for: Require named providers and model versions, plus notice before any model change.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
The M365 Copilot privacy documentation commits that prompts, responses, and data accessed through Microsoft Graph are not used to train foundation LLMs, including those used by Microsoft Copilot.
“Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.”
!How long do they keep your data?Ask the vendor
The Product Terms disclose that inactive service configurations or custom models (90 days without calls, modification or key) may be treated as expired for retention and deletion.
Requires written confirmation — see Before you sign ↓
“For the purposes of data retention and deletion, a Services configuration or custom model that has been inactive may at Microsoft's discretion be treated as an Online Service for which the Customer's subscription has expired.”
✓Who else can access your data?Clear
The Product Terms point to published Subprocessor lists (e.g. for Dragon Copilot) covering entities used in conjunction with the product.
“Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list”
!Where is your data processed?Ask the vendor
The Product Terms commit to storing Customer Data at rest within a configured Geo, disclosing that some services cannot be Geo-configured and may store backups in other locations.
Confirm in writing: Ask the vendor to state this in writing before signing.
“If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.”
“calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization”
!What happens in a security incident?Ask the vendor
Microsoft publishes security.txt routing to the MSRC researcher portal, bug bounty policy, coordinated vulnerability disclosure policy, and CSAF advisory feed.
Confirm in writing: Ask the vendor to state this in writing before signing.
“# Our Researcher Portal Contact: https://msrc.microsoft.com/report/vulnerability/new # Our PGP Key Encryption: https://msrc.microsoft.com/.well-known/csaf/openpgp/998D7EC1A516E3D17FF90480EF148D3CDE714E0D.asc Expires: 2026-09-23T16:00:00.000Z # Our Bounty policy Policy: https://www.microsoft.com/en-us/msrc/bounty/ # Our Coordinated Vulnerability Disclosure Policy Policy: https://www.microsoft.com/en-us/msrc/cvd”
Key findingsclick a row for the evidence
✓M365 Copilot answers the training question in its own documentationStrong
Prompts, responses and Microsoft Graph data are committed as not used to train foundation LLMs, with GDPR and EU Data Boundary compliance stated for commercial customers.
The core buyer question is answered with a product-scoped commitment, not inherited company prose.
“Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.”
“commercial customers, including the General Data Protection Regulation (GDPR) and European Union (EU) Data Boundary.”
✓The vulnerability-handling surface is exemplaryStrong
MSRC researcher portal, bounty with legal safe harbor, coordinated disclosure policy, and machine-readable CSAF advisories, all discoverable from security.txt.
This is the reference implementation of public vulnerability handling.
“# Our Researcher Portal Contact: https://msrc.microsoft.com/report/vulnerability/new # Our PGP Key Encryption: https://msrc.microsoft.com/.well-known/csaf/openpgp/998D7EC1A516E3D17FF90480EF148D3CDE714E0D.asc Expires: 2026-09-23T16:00:00.000Z # Our Bounty policy Policy: https://www.microsoft.com/en-us/msrc/bounty/ # Our Coordinated Vulnerability Disclosure Policy Policy: https://www.microsoft.com/en-us/msrc/cvd”
!Geo commitments carry explicit caveatsGap
Geo-configured storage is committed, but some services cannot be Geo-configured and backups may be stored elsewhere.
Which of the AI services in use honour the Geo boundary needs confirming per service.
Question for vendor: Which AI services in your deployment support Geo configuration, and where do their backups reside?
“If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.”
!Model suppliers behind Copilot are not named in the collected sourcesGap
None of the collected pages names the foundation-model suppliers behind Copilot experiences.
The provider relationship determines whose terms sit underneath the product.
Question for vendor: Which model providers or in-house models power the Copilot features in scope?
“Microsoft Copilot remembers details that matter to your daily life while keeping your personal data secure and protecting your privacy . You can always manage your privacy preferences in your Copilot Privacy settings.”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list”
?Technical dependency observed: GoogleObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Microsoft Responsible AI Dashboard to monitor and manage AI systems. Engage stakeholders across the organization and provide training on responsible AI principles and practices. The Microsoft Responsible AI Standard”
“committed to developing AI systems in a way that is transparent,”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score33
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Microsoft Copilot remembers details that matter to your daily life while keeping your personal data secure and protecting your privacy . You can always manage your privacy preferences in your Copilot Privacy settings.”
“Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Red teams think like hackers to help keep AI safe Read more”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
AI system description: vendor-evidenced, not yet independently corroborated.
Change management: not publicly evidenced.
Model10% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
Model provider transparency: not publicly evidenced.
Customer data15% of the score72
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.”
“For the purposes of data retention and deletion, a Services configuration or custom model that has been inactive may at Microsoft's discretion be treated as an Online Service for which the Customer's subscription has expired.”
“Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot.”
“calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the scoreorganisation-level evidence85
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“# Our Researcher Portal Contact: https://msrc.microsoft.com/report/vulnerability/new # Our PGP Key Encryption: https://msrc.microsoft.com/.well-known/csaf/openpgp/998D7EC1A516E3D17FF90480EF148D3CDE714E0D.asc Expires: 2026-09-23T16:00:00.000Z # Our Bounty policy Policy: https://www.microsoft.com/en-us/msrc/bounty/ # Our Coordinated Vulnerability Disclosure Policy Policy: https://www.microsoft.com/en-us/msrc/cvd”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the scoreorganisation-level evidence71
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“comprehensive set of more than 90 offerings.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“If Customer configures a particular service to be deployed within a Geo then, for that service, Microsoft will store Customer Data at rest within the specified Geo. Certain services may not enable Customer to configure deployment in a particular Geo or outside the United States and may store backups in other locations.”
“Law enforcement data requests View the number of requests for customer data we receive from law enforcement agencies.”
“commercial customers, including the General Data Protection Regulation (GDPR) and European Union (EU) Data Boundary.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 57 → up to 83 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 6 — registry checks and verification ladders, click to view
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
The claim on this Microsoft 365 Copilot report is SOC 2 Type II marked Yes for Office 365 Services, whose Product Terms definition names Microsoft 365 Copilot. The Service Trust Portal catalogue lists current Microsoft 365 SOC 2 Type 2 reports (period ended 30 Sep 2025) with a bridge letter covering the period to July 2026.
Checked against Microsoft Service Trust Portal (SOC report catalogue), Aug 27, 2026: Verified on the registry
The claim on this Microsoft 365 Copilot report is SOC 1 Type II marked Yes for Office 365 Services in the Product Terms. The Service Trust Portal catalogue lists current Microsoft 365 SOC 1 Type 2 reports (period ended 30 Sep 2025) with a bridge letter covering the period to July 2026.
Checked against Microsoft Service Trust Portal (SOC report catalogue), Aug 27, 2026: Verified on the registry
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry
Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry
Sources 18 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
