Frequently asked questions
Straight answers to what audit and compliance buyers ask most — about security, where your data lives, migration effort, integrations, pricing, and our compliance posture. Still have a question? Email hello@substantively.ai.
Security & the data boundary
What we hold, what we never hold, and how the boundary is enforced.
Where does our audit evidence actually live?
In your own Microsoft 365 / SharePoint tenant — never on our servers. Substantively stores workspace metadata (projects, controls, tasks, test conclusions, findings, risks, time entries, and links to files). Evidence files are linked by reference (a SharePoint URL plus file identifiers); opening a link loads the document from your tenant under your own permissions. There is no file upload to us, no blob storage, and no document-content persistence — this is architectural, not a policy. More on the security & data boundary page.
Is data encrypted?
Yes. Traffic is TLS-encrypted in transit, the metadata database is encrypted at rest, and Microsoft refresh tokens are encrypted at rest with AES-256-GCM. Because evidence never reaches us, the documents themselves stay protected by your own M365 encryption and controls.
How is one tenant isolated from another?
Every tenant-scoped table carries your organization ID and a Postgres Row-Level Security policy. The application connects with a database role that cannot bypass those policies, so a query outside your organization's context returns nothing — even if application code had a bug. The activity log is additionally append-only: the app's role holds no UPDATE or DELETE privilege on it.
What is your compliance posture? Are you SOC 2 certified?
SOC 2 Type II is in progress; we are not yet certified and do not claim a report we do not hold. In the meantime the architecture does much of the heavy lifting: evidence stays in your tenant, access is least-privilege, tenant isolation is enforced in the database, and the audit trail is append-only. We support security reviews and can sign a DPA. See the security page or email us for our current status and questionnaire responses.
Data residency & sub-processors
Where the metadata sits, and the short list of providers touching it.
Where is the metadata hosted, and is there an EU option?
The metadata database runs on managed PostgreSQL (Neon / Azure). An EU-region hosting option is available so your metadata stays within the EU. Remember the scope: only metadata is ever hosted by us — your evidence files always remain in your own M365 tenant, in whatever region your Microsoft 365 already uses.
Who are your sub-processors?
A deliberately short list: Clerk (authentication & org membership), managed PostgreSQL on Neon / Azure (application database), Paddle (billing, SaaS plan only), Resend (transactional email, optional), and Sentry (error monitoring, optional). Microsoft Graph is not a sub-processor — it is your own tenant, accessed with your own users' consent. The full table lives on the security page.
Can we keep the metadata entirely inside our own environment?
Yes. On the Enterprise plan, Substantively deploys as a dedicated single-tenant instance in your own cloud subscription — one application plus one PostgreSQL database — with billing, email, and telemetry integrations disabled. At that point no metadata leaves your environment either.
Migration & onboarding
Why there is no evidence migration, and how long setup takes.
How much evidence do we have to migrate?
None. Because evidence stays in your M365 / SharePoint, there is no document migration project, no bulk export, and no copy of your workpapers to move or re-secure. You point Substantively at where your files already live and link to them in place. This is the single biggest difference from evidence-vault tools that require you to upload everything into their cloud first.
How long does onboarding take?
A trial workspace is usable immediately — every feature, no card required. The one-time setup is light: an owner or manager connects Microsoft 365 and points the workspace at a SharePoint location for project folders. If your IT team blocks new apps, we provide a one-click admin-consent link (or a ready-to-send email) for a Global Administrator to approve the app once for the whole tenant.
Will it fit our audit methodology?
Substantively models the audit lifecycle — planning, controls registry, fieldwork, requests, findings/issues, risks, reports — so most teams map their existing methodology onto it directly. Enterprise onboarding includes tailoring to your methodology and frameworks. Imported framework control sets get you started without re-keying.
Integrations
Microsoft 365 is native; notifications reach Microsoft Teams today, with more integrations on the roadmap.
How does the Microsoft 365 integration work?
Natively, via Microsoft Graph. Sign-in uses your Microsoft work account (Entra ID). The app reads file names for linking and can create folders, copy templates, and accept uploads inside your tenant. Uploads travel directly from the user's browser to SharePoint — file content never passes through our servers, and our CI fails any change that tries to handle file bytes.
What Microsoft permissions do you request? Is it least-privilege?
Yes. Access acts as the signed-in user via delegated permissions, and for tenant-wide access we support Sites.Selected — so an administrator grants Substantively access only to the specific SharePoint sites you choose, not your entire tenant. That access can be revoked at any time from the Microsoft admin center.
Do you post notifications to Teams or Slack?
Microsoft Teams today. Request and finding activity can post to a Teams channel via an incoming webhook, so your team sees updates where they already work. Slack support is on the roadmap — tell us if it's a requirement and we'll weigh it in.
Do you integrate with Jira and ServiceNow?
Not yet. Findings and remediation items are tracked inside Substantively today; two-way sync with Jira and ServiceNow is on our roadmap. If it's a requirement for your rollout, talk to us about timing — it's a candidate for Enterprise onboarding.
Is there an API or webhooks?
Outbound webhooks to Microsoft Teams are available today. A documented public API and general-purpose webhooks for building your own automations are on the roadmap; if you have a specific integration in mind, we'd like to hear about it.
Pricing & plans
Predictable per-seat pricing, free viewers, no usage meters.
How are you priced?
Per auditor, per month, billed annually — predictable, with no usage meters. You pay for people who do audit work; viewers (audit committee, external assessors, auditees) are unlimited and free. A free 14-day trial covers the full product, and Enterprise adds a dedicated single-tenant instance. Full details on the pricing page.
What happens to our data when a trial or subscription ends?
Nothing is deleted. The workspace goes read-only until an owner restores access from billing, and your data is preserved. Since your evidence lives in your own M365 the whole time, your files are never affected at all.