We delete nothing we haven’t verified.
Every control on this page exists because an IT director asked us a hard question first. Read it the way your security team will.
Two-stage, least-privilege consent
Access is application-only Graph—no delegated user sign-in, no stored user credentials—and it comes in two stages. The scan consents to a read-only Entra app holding two read scopes: Sites.Read.All, and Organization.Read.All (which reads your licensed seat count to size your storage allowance—no files, no user data). A separate app with write access (Sites.ReadWrite.All, plus the same Organization.Read.All) is consented only when you choose to archive. Both registrations are visible in your own Entra admin center, and consent is yours to revoke at any time, which instantly cuts off all access.
SHA-256 before delete
Every file is copied, then re-hashed in object storage and compared to the source. Only on an exact match do we delete the original and write the stub. One mismatch halts the job, leaves the original untouched, and records the file.
Encrypted end to end
All traffic to Microsoft Graph and to object storage runs over TLS 1.2 or higher, and data lands encrypted at rest in object storage — either the dedicated bucket we provision for you (Sydney by default, any Wasabi region on request), or your own S3-compatible bucket under keys you control. Secrets are never written in the clear.
Backups nobody can delete
Optional immutable backups use S3 Object Lock in compliance mode: for the retention window you choose, stored copies cannot be altered or deleted by anyone — not a ransomware operator, not a rogue admin, not even us. The lock is enforced by the storage layer itself, not by policy.
Australian by default
Managed storage is provisioned in the Sydney region by default, with any Wasabi region available — US, EU, APAC — if your data needs to live elsewhere. Bring your own bucket and it lives wherever you put it. Data residency is a configuration you own, not a promise you have to take on trust.
RBAC + exportable audit
Role-based access and per-tenant isolation keep partners and clients separated. Every action—scan, copy, verify, delete, stub, skip—is written to an append-only log you can export in full.
What we will never touch.
Before a single file is considered for archiving, ArchiveBridge reads its compliance state from Microsoft Purview through the Graph API. Anything that carries an obligation to keep is removed from the candidate set and recorded—automatically, every run.
Retention labels
Files under a Purview retention label are detected and excluded. They stay exactly where they are.
Legal & eDiscovery holds
Items under a litigation, in-place, or eDiscovery hold are treated as off-limits. The hold is honoured at the source; we do not move data out from under it.
Quarantine, defined
“Quarantined” means the file stays in place, is flagged in the report, and is skipped with its reason logged. Nothing is hidden, moved, or altered—you can see precisely what was held back and why.
On the record
Every skip is written to the audit log with the file path and the reason (e.g. reason=legal-hold), so compliance and legal can check the exclusion list themselves.
Your escape hatch is built in.
Archived and backed-up files sit in standard S3 object format, in a dedicated Wasabi account created for you — with your bucket in it, not a shared pool or a proprietary vault. You can mass-restore everything back to SharePoint at any time, free (restores are never metered), read the objects directly with any S3 tool, and if you ever leave, that Wasabi account is handed over to you — it was never ours to keep. Leaving is a handover, not a negotiation.
Certifications: the infrastructure underneath is certified today — our hosting provider (RackCorp) and storage provider (Wasabi) both hold ISO 27001. ArchiveBridge’s own SOC 2 and ISO 27001 are on the roadmap as the customer base grows; the controls this page describes — least-privilege consent, verify-before-delete, immutable copies, exportable audit — are in production today and available for your own review.
Send it to your security team.
The fact sheet covers permissions, data flow, verification and residency — a direct download, ready to forward to procurement.
Deeper questions? Talk to an engineer — a human replies, not a sales sequence.