Ojja's trust center
What we read, what we never read, where the data goes, who accesses it, and what we do not do. Everything is dated; what changes is announced in the feed.
Five principles not up for negotiation
- Read-only, absolutely. No write access is requested, accepted or held. The exact rights per source are written down; non-writing is tested at kickoff. Our recommendations are carried out by your teams or your managed service provider, never by us.
- Minimization by design. We read registers and configurations, never your documents, never your business data. We read configurations, definitions and metadata: which systems exist, what they are allowed to do, who created them. Never the data these systems process, never a conversation, never the content of a document, never a secret.
- Never individual monitoring. No usage report is kept at the level of a person: each line is counted on reading, then forgotten. Ojja reads only the sign-in logs of the last 28 days, and keeps only counts per application and per department. The exposure statement measures the exposure of the organization, not the behavior of employees: it can be presented to your works council and your DPO without friction.
- Raw data is evidence, not an asset. Extracted data is sealed by fingerprint, used, then purged. We never capitalize on your data.
- Strict separation per engagement. One vault per client, one key per client, no mixing.
Your employees' data
In what we read from your tools, we keep no employee identifier. Usage reports are aggregated; for an application an employee has authorized, we keep the type of authorization, the data it reaches and the number of accounts, not their identity. We never read content: email, document, message, conversation with an assistant. Usage is never reported for a group of fewer than ten people. The only people known to Ojja are those who use the workspace: the person who owns AI, the readers you invite and, with the portal, the employees who sign in to it. Ojja measures the AI in place in the organization, never the behavior or performance of a person.
What we read, source by source
For tools outside Microsoft, you declare the list; each line of the register then carries the mention “declared”. The declaration is never the source of truth: what can be read is read.
Microsoft 365
read from the free readout
We never touch it
- Subscriptions and the organization's identity
- Accounts and assigned licenses, with their department; each account's identifier is hashed on reading and never kept
- Microsoft's announcements to your administrator (Message Center)
- Microsoft 365 Copilot usage, counted by application and by department
- Applications in your tenant and the consents granted to them
- Sign-in logs only, aggregated by application and by department
- New AI application connected:
- read every day
- Usage billing turned on:
- read every week
- Vendor terms changed:
- on each publication
- New model behind a feature:
- read every day
- New data access:
- read every day
Console export of the usage report, provided by your administrator
Copilot Studio and Agent Builder agents
read with Ojja Watch
We never touch it
- Inventory of your agents (Copilot Studio, Agent Builder)
- New AI application connected:
- read every week
- Usage billing turned on:
- read every week
- Vendor terms changed:
- on each publication
- New model behind a feature:
- read every week
- New data access:
- read every week
CSV export of the inventory, provided by your administrator; without either, agents are marked “not read”.
The permission manifest
Ojja Reader
We never touch it
Endpoints
GET https://graph.microsoft.com/v1.0/subscribedSkusGET https://graph.microsoft.com/v1.0/usersGET https://graph.microsoft.com/v1.0/directory/subscriptionsGET https://graph.microsoft.com/v1.0/admin/serviceAnnouncement/messagesGET https://graph.microsoft.com/v1.0/organizationGET https://graph.microsoft.com/v1.0/copilot/reports/getMicrosoft365CopilotUsageUserDetail(period='D28')GET https://graph.microsoft.com/v1.0/copilot/reports/getMicrosoft365CopilotUsageUserDetail(period='D180')GET https://graph.microsoft.com/v1.0/servicePrincipalsGET https://graph.microsoft.com/v1.0/applicationsGET https://graph.microsoft.com/v1.0/oauth2PermissionGrantsGET https://graph.microsoft.com/v1.0/auditLogs/signIns
Manifest v1.0, September 30, 2026
The documents
The permission manifest
The exact list of Microsoft Graph permissions requested, explained line by line.
The data processing agreement (DPA)
The data processing agreement for the readout and Ojja Watch, version 1.0.
The list of subprocessors
Who processes what, where, under which contract.
The purge statement
Raw data is purged on day 30; the statement records it.
Delivered with each assessment.
Ojja's AI register
Our own AI features and agents, in the register format.
In preparation.
Verification of signed documents
Each signed document will carry its verifiable reference.
In preparation.
Subprocessors: annex 3 of the DPA (in French)
| Sous-traitant | Prestation | Lieu de traitement |
|---|---|---|
| Scaleway (France) | Hébergement, base de données, coffre de secrets, modèles d'IA | France |
| Brevo (France) | Courriels de service : invitations, rappels, alertes | Union européenne (OVH en France et en Allemagne, Google Cloud en Belgique) ; voir la liste officielle des sous-traitants annexée au DPA de Brevo |
| Yousign (France) | Signature électronique des contrats Ojja Watch | France, selon l'éditeur ; voir la liste officielle des sous-traitants annexée au DPA de Yousign |
What a statement says, and what it does not say
“record limited to the scope read, at its date”
Each document carries its scope statement. Each statement also carries its date of validity: it establishes what existed at that date; it says nothing about what has been put into service since. An exposure statement describes a dated state, established on the platforms read and the declared items, and each framework it cites points to its text. It replaces neither the report nor your own impact assessment, and it does not certify conformity. We prefer a document that is precise about what it covers to a document that is reassuring about what it does not cover. Ojja does not practice law. Ojja does not provide legal advice: it records and documents; how the law applies to your situation is for your counsel to determine.
In practice
- The audited party does not choose the evidence. We extract directly from your platforms; we do not work on prepared exports. Each statement carries a reference number derived from the fingerprint of the extracted data batch, and a verification contact: a third party can check that a document is authentic without ever accessing your data.
- AI in our own processing. Consistency requires it: AI assists our processing (reading, matching), it decides and qualifies nothing: the rules decide, humans sign. Three levels to choose by contract: processing in our sovereign infrastructure, full processing in your own tenant, or strictly without AI, at no extra cost.
- Reversibility. Your register belongs to you: full export at any time, API access, no lock-in to a captive tool. It is written in the contract, and it can be checked before signing.
- Independent from vendors. We read their tools, we sell none of them.
- Contractual framework. Confidentiality agreement, data processing agreement, written scope of each reading.
Hosting and sovereignty
- Sovereignty The data read in your tools is processed and hosted in France, at Scaleway (hosting, database, secrets vault, AI models). Our other subprocessors are European: Brevo (service emails: invitations, reminders, alerts), Yousign (electronic signature of Ojja Watch contracts). The public site ojja.ai receives no data read in your tools; its forms are sent directly to Brevo. List updated with advance notice.
- Retention Free readout not followed by a subscription: no reading after delivery, a reminder on day 14 to remove access, raw extraction purged on day 30, readout kept twelve months in your workspace and deleted sooner on request. Ojja Watch: snapshots, log and decisions kept during the subscription then twelve months, unless you ask for their deletion or return sooner, full export always available before the purge. Sealed report: only its fingerprint and its date are kept for five years.
- “Your data never leaves your IT system” mode. For regulated sectors (banking, insurance, healthcare), our collector runs inside your IT system, under the supervision of your administrator: your raw data never leaves it.
What we do not do
We never administer a tenant. Ojja does not provide legal advice. We sell no license. We build nothing.
Trust center, version 1.2 · September 30, 2026. This page evolves with the product; each version is dated.
A security question before starting an assessment?
Your CISO can write to us directly: securite@ojja.ai