← Resources

Trust and control

Security overview

A public overview of signed components, offline licensing, package provenance and organization trust controls.

Public security model

  • Signed components — product binaries can enforce signed-binary trust and Team ID expectations.
  • Offline licensing — licensed workflows can operate without continuous cloud dependency.
  • Package provenance — generated outputs can carry product and license metadata.
  • Integrity controls — protected package and configuration changes can be detected.
  • Organization trust — tenant- and organization-bound controls can be applied where configured.

Data handling

Authoring and packaging are designed to operate locally. Network access is required only for workflows that communicate with external services such as Microsoft Graph.

Internal license formats, stamp algorithms, trust-verification implementation and build-pipeline details are intentionally not public.