Legal / Security & DPA
Security & DPA overview
How we host, encrypt, isolate, and access data for the Magicite add-ons, and how to get a formal Data Processing Agreement.
Security is foundational to how Magicite is built and run. This overview summarizes our approach for the add-ons and this service. For how we handle personal data, see our Privacy Policy.
Hosting
Our service runs on Microsoft Azure, using Azure's compute, identity (Microsoft Entra), and infrastructure. We rely on Azure's physical and platform security controls and keep our footprint minimal.
Encryption
Data is encrypted in transit using current TLS, and at rest using platform-managed encryption. License-validation traffic between the add-ons and our service is likewise encrypted in transit.
Tenant isolation
A customer corresponds to a Microsoft Entra tenant. We scope and isolate customer data by tenant so that one organization's identity, entitlements, and telemetry are not accessible to another.
Least-privilege access
Access to production systems and customer data is restricted to the minimum needed to operate the service. We apply role-based, least-privilege access and keep secrets server-side; they are never sent to the browser.
Signed-license phone-home model
The add-ons are delivered as signed deployable packages. Once installed, they periodically contact our service to validate their license and to send PII-free operational telemetry: versions, counts, environment identifiers, and health signals. The telemetry is designed to exclude personal data and your business records: it confirms the software is licensed and healthy, not what your data contains. Enforcement is soft by design, favoring warnings and a grace period over an abrupt hard stop.
Data Processing Agreement
Our Data Processing Agreement (DPA), including our current sub-processor list and applicable data-protection terms, is published at magicite.tech/dpa. Customers who need a countersigned copy on file can contact us and we will execute the current version.
Certifications
We hold no formal security certifications today. The controls described on this page are what we actually operate, and we would rather say that plainly than imply an audit that has not happened. We rely on Microsoft Azure's platform certifications for the infrastructure layer, and we will evaluate formal certification of our own service as the customer base grows.
Reporting a concern
If you believe you have found a security issue, please email security@magicite.tech so we can investigate promptly.