Metadata-only M365
Purview · Entra · audit indices — evidence index on every TLE, no mailbox custody.
AvailableProcurement diligence · honest scope
Metadata-only Microsoft 365 processing. Export bundles fail closed on tamper. No custody, payment rails, or certifier claims — Available · Planned · Out of scope only.
Procurement diligence
Honest Available · Orientation · Planned · Out of scope — what legal, security, and procurement reviewers inspect before pilot sign-off.
Purview · Entra · audit indices — evidence index on every TLE, no mailbox custody.
AvailableBoard PDF and procurement ZIP fail verification when tampered — by design.
AvailableEU AI Act Art. 12 · NIST AI RMF · ISO 42001 mapping — orientation only, not certifier claims.
OrientationCryptographic receipt chain — planned product capability.
PlannedIndependent audit planned — not yet completed.
PlannedNo payment execution, MSB, asset custody, or money-transmission claims.
Out of scopeData handling
Purview · Entra ID · audit log indices — no mailbox content custody. See Privacy and Canada trust notes.
| Surface | Posture |
|---|---|
| M365 mailbox / content custody | Out of scope |
| Purview · Entra · audit metadata index | Available |
| Subprocessor list & retention | Orientation |
Export integrity
Board PDF and procurement ZIP include integrity checks. Walkthrough: offline verify guide.
1
Board PDF + procurement ZIP + manifest from workspace or pilot tenant.
2
Unmodified bundle returns export_integrity: PASS.
3
Any alteration fails verification — by design for procurement reviewers.
Honest certification posture
We produce governance artifacts — not company ISO/SOC certification claims.
| Control / capability | Posture |
|---|---|
| TLE v1 + workspace UI | Shipped |
| Export integrity fail-closed | Shipped |
| M365 metadata-only processing | Shipped |
| Board PDF + procurement ZIP | Shipped |
| Framework citations (NIST · ISO orientation) | Orientation |
| SOC 2 Type II | Planned |
| ISO 27001 / 42001 certification (Noetfield as certifier) | Out of scope |
| Ed25519 / Merkle transparency log | Planned |
Non-confidential intake · include your Request ID · Copilot Governance Pack ($2k–10k · 90 days · board PDF), Trust Brief ($10k), federal or MSP lane · operations@noetfield.com