Security

Reporting and basic security controls.

Last updated: 2026-05-10
Security is a shared responsibility. If you believe you found an issue, report it through your engagement support contact with clear reproduction steps.
Back to portal
Quick links
FAQ
Common questions
Support
Ask Fop
Architecture
Deployment paths
RFS
Request a scenario
Security
Report concerns
Privacy
Data handling
Terms
Usage conditions
Accessibility
Feedback channel
Partners
CSP marketing
Legal
Policies & agreements
Report an issue
If you believe you found a security issue, report it through your engagement support contact. Provide clear reproduction steps and avoid including sensitive data.
Security controls in place

A layered set of customer-relevant controls protects your data from the browser to your own storage. Each control is summarised below with the specifics it enforces.

◆

Secure transport & network boundary

Everything the portal sends travels over encrypted channels with hardened browser defaults.

  • ✓HTTPS/TLS enforced for portal delivery and every API call
  • ✓Security headers (HSTS, referrer, content-type) applied by default
  • ✓Browser calls locked to a single public API base URL (CORS-scoped)
  • ✓No inbound ports or privileged listeners exposed to the customer network
◈

Minimal application surface

The portal ships as a static export, so there is no server runtime to attack.

  • ✓Static-hosting-safe build (no server-only execution in the portal)
  • ✓No tenant credentials or privileged secrets embedded in the UI
  • ✓Client-side interaction only — no privileged admin sessions in the browser
  • ✓Dependency hygiene and automated CodeQL scanning on every change
◎

Customer-owned data destinations

Your artifacts land in storage you control — MSC does not park customer content.

  • ✓Outputs routed to Azure Blob, AWS S3/GCS, SharePoint, or your file shares
  • ✓No long-term storage of customer datasets on MSC infrastructure
  • ✓Tenant admin credentials and privileged secrets are never retained
  • ✓Retention, approvals, and governance stay under your policy model
◐

Least-privilege access

Access is scoped to the engagement, with no hidden dependency on super-admin rights.

  • ✓Least-privilege posture by design across the portal and API
  • ✓No dependency on standing super-admin or global-admin access
  • ✓Engagement-scoped access aligned to the work being performed
  • ✓Clear separation between portal UI and backend API responsibilities
◇

Provenance & auditability

Deterministic, ID-tracked artifacts make every run easy to review and sign off.

  • ✓Journey IDs and operational metadata for every run
  • ✓Deterministic artifact bundles — repeatable, reviewable outputs
  • ✓Clear provenance from assessment through to export
  • ✓Structured reporting metadata published at /.well-known/security.txt
◒

Safe-use guardrails

The workflow steers sensitive data away from free-text and out of the browser.

  • ✓Do not enter credentials, secrets, or regulated personal data in free-text fields
  • ✓Sensitive data stays out of the browser and out of MSC storage
  • ✓Report suspected issues through your engagement support contact
  • ✓Provide clear reproduction steps without including sensitive data
Safe use
Do not enter credentials, secrets, or regulated personal data into free-text fields.
Structured reporting metadata is published at /.well-known/security.txt.
2026 LuiT || ₷©®•Modern Support Consult•Hosted on Microsoft Azure + GitHub Enterprise
FAQSupportArchitectureRFSSecurityPrivacyTermsAccessibilityPartnersLegalTRIX
Support details(version & routing)
APImsc-portal-api-d7g5fudfa7eufufa.westeurope-01.azurewebsites.net
Builda30883e1@20260812T141507Z
LaneMicrosoft Commercial Marketplace (ISV Success)
Billing & licensing(public summary)
This portal provides structured assessments and actionable guidance. Results depend on what is observable and what changes are implemented in your environment.
Results depend on inputs
  • Online scenarios measure available signals (for example: public DNS records) and report what is observable at the time of the run.
  • Guidance describes recommended steps; applying them may require configuration changes, permissions, vendor behavior, and timing.
  • Outcomes are influenced by multiple moving parts; we focus on measurable improvements, defensible choices, and clear evidence you can act on.
How costs are calculated (customer view)
  • Microsoft Commercial Marketplace: Microsoft is the merchant of record. Microsoft handles billing, taxes, invoicing, refunds, plan changes, and cancellation under your Microsoft Customer Agreement. Manage the subscription from Azure Portal → SaaS subscriptions.
  • Plans & metering: per-plan price and any metered dimensions are visible in the Marketplace offer at checkout. Charges appear on your Microsoft invoice.
  • Customization-supported scenarios: scope and pricing are confirmed with you (in writing) before work begins, and only change if scope assumptions materially change.
  • Taxes are calculated and collected by Microsoft. Marketplace invoices are the source of truth.
Fairness & exceptions
Reconciliation is based on the agreed deliverables and the available inputs. If customer-side deliverables (access, approvals, change windows) are delayed after being identified as blockers, we may pause measurement or re-baseline the delivery window. We prefer fast, transparent review and adjust when the facts support it.
License scope
Some scenarios and deeper artifacts are intentionally restricted in public mode. For customization-supported engagements, licensing/procurement and exact deliverables are confirmed before work begins. If you need enterprise-wide terms or invoicing, use Support.
Why Modern Support Consult
Microsoft-first, on-prem friendly
MSC is built around Microsoft infrastructure and cloud operations, with on-premises realities treated as first-class. Built by an Exchange-focused specialist (~30 years IT; ~20 years Microsoft messaging & integration).
Curated, regulated guidance
Not random tips: curated and cross-compared to reduce noise and keep actions defensible.
Benchmarking + checklist outputs
Scenarios benchmark posture and produce checklist-style remediation aligned with mainstream security/ops methods.
Quadral method (Codex / Metaflow-ready)
Evidence → traceable outcomes: signals, checks, decisions, guidance, exceptions. Designed for consistent benchmarking and audit-friendly reasoning.
Use Close to return to the portal.