Security and Data Handling

Resource Lens is a multi-tenant Azure SaaS application operated by Firesub AB. Customer Azure resources remain under customer control; the service reads only the scopes and evidence sources explicitly selected during setup.

Processing boundary

  • Authentication uses Microsoft Entra ID. Tenant and user claims are validated before workspace data is accessed.
  • Every persisted analysis, recommendation, evidence record, audit event, artifact, and billing record is tenant-scoped.
  • Azure inventory, cost, Advisor, Monitor, activity-log, and pricing evidence is used only to provide and operate the customer's Resource Lens workspace.
  • Generated commands and infrastructure artifacts are review-only. Resource Lens does not execute them against customer resources.

Regional processing and storage

The workspace region selected during setup controls the configured regional Azure services used for database, storage, analysis, and hosted-model processing where those services support the selected region. Operational routing and Microsoft Marketplace processing may use Microsoft's global service infrastructure.

Encryption and credentials

  • Supported public endpoints use HTTPS.
  • Service credentials and certificates are stored in Azure Key Vault and are not exposed to the browser.
  • Customer access tokens are used for the requested operation and are not written to analysis evidence or application logs.
  • Stored application data uses the encryption capabilities of the underlying Azure SQL and Azure Storage services.

AI processing

Deterministic calculations and validation remain authoritative. Hosted models are used for bounded analysis and summarization, and the portal identifies missing evidence, assumptions, and required validation. Secrets and access tokens must not be included in model prompts.

Retention and deletion

Analysis history and evidence remain available while the workspace is active so findings can be audited and rerun. Workspace reset immediately locks access, schedules permanent deletion of workspace database records and archived analysis data after a seven-day recovery period, and reports any Azure role assignments that require customer cleanup.

Customer controls

Authorized owners can narrow subscription scope, revoke optional evidence roles, remove all Resource Lens access from a subscription, manage user app roles in Entra ID, cap metered AI overage, or start workspace reset.