Skip to main content

User Knowledge Base

Security and Compliance

BlueVoyant AI AI recognizes security requirements and compliance regulations.

Identity and Authentication
  • The application sends authentication to all resources through Managed Identity. There are no secret keys or passwords in the configuration.

  • All calls between services go through an API Management (APIM) gateway, for service-to-service authentication.

  • Local settings are kept in a local file, which is not sent to BlueVoyant.

Data Access and Control
  • Agents access your security incident data only through managed API endpoints with restricted role-based authentication and OAuth scopes. Direct system access is prohibited.

  • Microsoft Defender data is accessed through KQL queries in a specified query interface. You can audit all data access.

  • The AI agents run in a Microsoft managed enterprise AI platform in the Microsoft Azure trust boundary.

Compliance and Security Audits
  • Each agent call is logged in an SQL table (agents_threads) with a unique thread ID, the incident ID, status, timestamps, and token count for a full audit trail.

  • Application telemetry is sent to Application Insights with structured JSON for logs.