Skip to content

Compliance

How Dockli is published and verified — and how to run your own security review. Straight about what's proven and what isn't.

Last updated: July 2026

Dockli is published with a verified publisher identity and a least-privilege permission posture. This page describes how publisher verification works — and is deliberately honest about which assurances Dockli can and cannot claim today.

Publisher-verified in Microsoft Entra

Dockli is published by Tiny Tugboat with a publisher-verified domain in Microsoft Entra. The Entra app registration carries a verified-publisher marking, so when an administrator sees Dockli’s consent screen, it clearly and verifiably identifies who is asking for permissions — not an anonymous or spoofable app name. This is the same publisher-verification mechanism Microsoft uses across the app ecosystem to give admins an attributable, trusted consent prompt.

See Tenant-wide admin consent for what that consent covers and who can grant it.

Least-privilege posture

The security architecture is covered in depth across this section, but the compliance-relevant summary is:

  • Delegated permissions only. Every Microsoft Graph scope is delegated — Dockli acts as the signed-in user and never as a standing application identity. There is no app-only grant with tenant-wide access to your content. See Permissions and scopes.
  • Incremental consent. Higher-impact scopes (sending mail, Teams messaging, people lookup, SharePoint recycle bin) are requested only when the feature is first used — not up front.
  • No tokens in the UI, loopback-only networking, DPAPI encryption at rest. See Security architecture and Authentication and tokens.
  • Data residency: your data stays in your Microsoft 365 tenant. File content is read live through Graph and is not copied to Dockli servers. See Data handling and residency.

An honest note on certifications

Dockli does not currently claim formal third-party certifications such as SOC 2, ISO 27001, or HIPAA compliance. We would rather describe our architecture accurately than imply an attestation we don’t hold.

What we can say with confidence:

  • The architecture is designed for a security-conscious M365 environment — delegated least-privilege access, no tokens in the browser, loopback-only surface, encryption at rest, and a governed AI gateway.
  • Dockli’s vendor identity is backed by a publisher-verified domain in Microsoft Entra, so the party your admins consent to is attributable and trusted.

We won't overstate this

If a specific certification or attestation is a hard requirement for your organization, tell us during a review. We’ll be direct about where we are rather than claim a certification Dockli doesn’t hold.

How to run a security review

The most efficient way to review Dockli is to walk the architecture with us, question by question:

  1. Read this section end to endSecurity architecture, Authentication and tokens, Permissions and scopes, Data handling and residency, and AI security — for the technical model.
  2. Review the exact Graph scopes your users would consent to in Permissions and scopes, and the one-time admin approval in Tenant-wide admin consent.
  3. Allowlist and confirm egress using Endpoints to allowlist — the complete set of hosts Dockli reaches.
  4. Book a demo and bring your security team. We’ll cover the architecture end to end and answer specifics against your requirements.

Bring your questions

A live review with your security team is the fastest path to sign-off. We’ll walk sign-in, token handling, the loopback boundary, the AI gateway, and data residency in whatever depth you need.

Still stuck? Email support@dockli.io — a human replies within one business day. Or book a demo.