A detailed security, privacy, and compliance overview for customer security reviews.
AnalysisPlace develops and operates Microsoft Office document automation software, including the Excel-to-Word Document Automation add-in and related document automation services. This security page is intended to help customers, IT administrators, procurement teams, and security reviewers understand how AnalysisPlace protects customer data, manages risk, and operates its services.
Our security approach is based on data minimization, Microsoft Azure managed services, encryption, restricted administrative access, security monitoring, secure development practices, documented change control, vulnerability management, incident response planning, and periodic review of operational controls.
This page is intentionally detailed, but it does not publish sensitive operational information such as internal network diagrams, public IP ranges, firewall rule details, security monitoring configurations, vulnerability findings, administrator account names, or proprietary incident response playbooks.
AnalysisPlace performs the following security and compliance activities on a recurring schedule. Frequencies represent our standard internal review cadence and may be increased following significant changes, security events, customer requirements, or changes to the Microsoft 365 App Compliance Program.
| Security operation | Standard cadence | Purpose |
|---|---|---|
| Vulnerability scanning of public-facing services | Quarterly, and after significant changes where appropriate | Identify and remediate web application, configuration, and externally visible security risks. |
| Application dependency and library review | Quarterly or semi-annually, depending on component type and risk | Review server-side components and client-side libraries for outdated versions and known vulnerabilities. |
| Security log and alert review | Quarterly, with ongoing alert monitoring | Review relevant logs, risky sign-ins, service health information, cloud alerts, and security anomalies. |
| Account and access review | Semi-annually and after personnel or role changes | Confirm that production access remains limited, appropriate, and aligned with least privilege. |
| Network and cloud security control review | Semi-annually | Review access restrictions, storage exposure, cloud security recommendations, and other network-related controls without publishing sensitive rule details. |
| Secure development and security awareness training | Annually | Ensure personnel involved in development, security, and support continue to receive relevant security training. |
| OWASP Top 10 / secure design assessment | Annually and during major feature or architecture changes | Evaluate the application against common web application security risks and secure design principles. |
| Information security risk assessment | Annually | Identify, assess, document, and treat security risks affecting the service, data, operations, and vendors. |
| Incident response tabletop exercise | Annually | Practice incident response roles, communication, investigation, containment, recovery, and lessons learned. |
| Business continuity and disaster recovery review | Annually | Review continuity plans, recovery procedures, critical services, responsibilities, and plan effectiveness. |
| Backup restore testing | Annually, using a representative restore scenario | Validate backup reliability and recovery procedures without exposing production customer data. |
| Data retention and deletion audit | Semi-annually or annually, with automated deletion operating continuously | Verify that data retention and deletion processes are operating as documented. |
| Automated backups, logging, alerting, and deletion jobs | Ongoing / automated | Maintain continuous operational controls for availability, auditability, and data minimization. |
The AnalysisPlace Excel-to-Word Document Automation add-in is Microsoft 365 Certified. Microsoft’s public app certification listing provides app security, compliance, privacy, identity, and data handling information for the add-in.
Customers may review the public listing here: Microsoft 365 App Certification listing .
Microsoft 365 Certification reviews both app behavior and publisher practices. For customers, this certification is useful because it provides an independent Microsoft review path for information that is commonly requested during vendor security reviews.
The primary AnalysisPlace product covered by this page is the Excel-to-Word Document Automation add-in, which helps users update Word and PowerPoint documents from Excel data, calculations, tables, charts, images, and other content. The add-in is used inside Microsoft Office and interacts with AnalysisPlace services as needed for authentication, usage tracking, account management, cloud transfer, and cloud document processing.
This page also applies to related AnalysisPlace document automation APIs, the AnalysisPlace website, the customer account administration portal, and supporting Azure-hosted services that store, process, or transmit customer data.
AnalysisPlace is designed to minimize the amount of customer data collected and retained. In normal use, the add-in may process several categories of data: account information, subscription and billing-related identifiers, usage statistics, configuration settings, document content submitted for transfer or cloud processing, and document templates uploaded by users or business administrators.
Most customer security reviews focus on whether document content is uploaded, who can access it, how long it is retained, and whether it is encrypted. AnalysisPlace addresses those questions through optional direct transfer, short cloud retention periods, encryption in transit and at rest, restricted administrator access, and documented deletion procedures.
Where supported by the user’s Microsoft Office environment, the add-in can use a direct transfer method. Under this method, submitted content is stored locally using the browser storage environment controlled by Office on the user’s device. The document content is not uploaded to AnalysisPlace cloud servers for that transfer.
When direct transfer is not available or when a feature requires server-side processing, document content may be uploaded to AnalysisPlace-controlled Microsoft Azure services. Cloud transfer and cloud processing are protected using encrypted transport, encrypted storage, restricted access, and automatic deletion procedures.
Customers can learn more about transfer behavior, direct transfer, cloud transfer, upload settings, and verification options at Content Uploading and Content Transfer Method .
| Data category | Examples | Purpose | Storage / retention summary |
|---|---|---|---|
| Account and business information | Name, email address, company name, subscription information, account settings | Account creation, subscription administration, support, user access control, and service operation | Stored in Azure SQL and retained according to AnalysisPlace data retention policies |
| Usage and session data | Feature usage, session details, browser and Office version information, access times, error reporting data | Service operation, troubleshooting, subscription tier enforcement, usage reporting, fraud prevention, and product improvement | Stored in Azure SQL and retained according to documented usage data retention rules |
| Document content for direct transfer | Excel content submitted to update Word or PowerPoint where direct transfer is supported | Document update functionality | Processed on the user’s device and not retained by AnalysisPlace |
| Document content for cloud transfer | Excel content temporarily uploaded so Word or PowerPoint can retrieve it | Document update functionality when direct transfer is unavailable or disabled by the Office environment | Temporarily stored in Azure App Service storage and automatically deleted |
| Cloud-created or cloud-updated documents | Documents generated or updated by AnalysisPlace cloud services | Template-based document creation and cloud update functions | Temporarily stored in Azure Blob Storage and automatically deleted |
| Document templates | Word and PowerPoint template files uploaded by users or business administrators | Enable template-based document generation and business-controlled document automation | Stored in Azure Blob Storage and retained while the account or business relationship remains active, subject to retention rules |
| Payment information | Subscription and payment processor identifiers | Subscription management and billing reconciliation | Credit card details are handled by payment processors, not stored by AnalysisPlace |
For details, see our Privacy Policy.
AnalysisPlace encrypts customer data in transit and at rest. Public-facing services use HTTPS/TLS, and AnalysisPlace uses Microsoft-managed certificates for custom domains and Azure-hosted services where applicable. Data stored in Azure SQL, Azure Blob Storage, and Azure App Service storage is encrypted using Microsoft Azure-managed encryption capabilities.
AnalysisPlace does not publish private keys or internal certificate details on public pages. Certificate and key management is handled through Microsoft Azure managed services rather than customer-accessible or publicly disclosed key material.
AnalysisPlace production services are hosted primarily on Microsoft Azure platform services. The production architecture uses platform-managed services for web applications, database storage, and file/blob storage. Using managed Azure services reduces direct operating system administration responsibility and allows Microsoft to manage many underlying infrastructure security functions.
AnalysisPlace does not publish detailed network diagrams, cloud resource inventories, public IP ranges, internal firewall rules, or administrative procedures on this public page. Customers that require additional confidential technical information may contact AnalysisPlace for review under an appropriate confidentiality arrangement.
Access to production resources is restricted to authorized AnalysisPlace personnel with a business need. Administrative access uses unique accounts, least privilege principles, and multi-factor authentication. AnalysisPlace maintains internal access review records and periodically reviews access to Azure, Microsoft 365, and related systems.
AnalysisPlace separates privileged administrative use from ordinary daily work where practical. Access to production data and production resources is not granted to contractors or third parties unless there is a specific approved business need, appropriate controls are in place, and access is limited to the minimum necessary scope.
AnalysisPlace maintains separate development/test and production environments. Development and testing activities are performed outside the production environment. Production customer data is not used in development or testing environments. Production deployments follow documented change control and testing procedures.
AnalysisPlace uses documented change control for significant production changes. The change control process includes planning, risk assessment, affected systems, testing, approval, deployment steps, back-out considerations, and post-change review. Low-risk editorial or non-material changes may follow a lighter process, but security-impacting, production-impacting, or customer-impacting changes are reviewed before deployment.
Production deployments are performed only after development and testing activities are complete. AnalysisPlace also maintains procedures for backing up production code or configuration before significant deployment activity so changes can be reversed if necessary.
AnalysisPlace follows a secure software development process that considers security during planning, design, implementation, testing, deployment, and maintenance. New features and significant code changes are reviewed against common secure development principles, including authentication, authorization, input validation, output handling, encryption, logging, error handling, and least privilege.
The development process incorporates secure coding awareness, review of OWASP Top 10 risks, use of Visual Studio analysis capabilities for server-side code, browser developer tools for web client issues, and dynamic application security scanning for externally accessible web services.
AnalysisPlace personnel involved in development and security operations complete periodic security awareness and secure development training. Training topics include protecting identities, recognizing phishing, secure coding, incident response, and cloud security practices.
AnalysisPlace reviews application dependencies, server-side components, client-side JavaScript libraries, Azure security recommendations, and public-facing services on a recurring basis. Because AnalysisPlace uses Azure platform services, Microsoft manages many underlying operating system and infrastructure patching responsibilities. AnalysisPlace is responsible for application code, libraries, configuration, and customer-facing service security.
Application dependencies are reviewed for outdated versions and reported vulnerabilities. Server-side dependencies are reviewed using development tooling, and client-side libraries are reviewed against version and vulnerability information from trusted sources. Vulnerabilities are prioritized based on severity, exploitability, exposure, and customer impact.
AnalysisPlace performs recurring vulnerability scanning of public web applications and supporting services using a combination of web application scanning, cloud security recommendations, code analysis, and manual review. Public-facing security summaries avoid disclosing detailed vulnerability findings, exploit details, scan screenshots, or internal remediation records.
AnalysisPlace uses Azure-native logging, monitoring, and alerting capabilities to monitor application services, storage, database activity, authentication events, and cloud resource activity. Security-relevant alerts are sent to authorized personnel for review and investigation.
AnalysisPlace retains security event logs according to documented retention practices and performs periodic reviews of logs, alerts, risky sign-in information, service health notices, and cloud security recommendations. Public materials do not disclose detailed detection logic, alert rules, security monitoring configurations, or internal investigation procedures.
AnalysisPlace maintains a documented security incident response process covering detection, analysis, containment, eradication, recovery, remediation, notification, and lessons learned. Incident response responsibilities are assigned internally, and team members periodically review the process and participate in tabletop exercises.
If AnalysisPlace becomes aware of a security incident affecting customer data, AnalysisPlace will investigate, take appropriate containment and remediation steps, and communicate with affected customers and relevant parties as required by contract, law, and applicable certification or marketplace requirements.
AnalysisPlace does not publish detailed incident response playbooks, escalation procedures, contact trees, or internal forensic procedures on public pages. Customers may request additional information through the standard security review process where appropriate.
AnalysisPlace maintains documented business continuity and disaster recovery planning for critical business functions and Azure-hosted services. The plan identifies critical services, assigns responsibilities, describes backup and recovery approaches, and includes periodic review and testing.
Azure platform backup and recovery capabilities are used for application services, databases, and storage where appropriate. Backup procedures and restore testing are reviewed periodically. AnalysisPlace does not publish uncommitted recovery-time promises or internal recovery procedures on public pages.
AnalysisPlace retains data only as long as reasonably necessary for service operation, security, compliance, billing, fraud prevention, customer support, and legal purposes. Retention periods vary by data type. Account and usage data may be retained longer than temporary document content because it is needed for subscriptions, support, fraud prevention, and business records.
Temporary document content used for cloud transfer or cloud document processing is retained for a short period and automatically deleted. Document templates are retained while needed for the account or business relationship and are deleted according to documented retention and inactivity rules.
Data deletion is performed through a combination of application logic, stored procedures, Azure lifecycle rules, and cloud platform retention policies. Backup copies may remain temporarily in Azure-managed backups until backup retention periods expire.
AnalysisPlace publishes a privacy policy that explains what personal data is collected, why it is collected, how it is used, how long it is retained, how users can exercise privacy rights, and how users may contact AnalysisPlace. Customers can review the privacy policy at AnalysisPlace Privacy Policy.
AnalysisPlace supports data subject access requests, account deletion requests, and privacy-related inquiries through its published contact process. AnalysisPlace does not sell, rent, or lease customer lists or customer personal data to third parties.
AnalysisPlace relies primarily on Microsoft Azure, Microsoft 365, and Microsoft development tools for hosting, productivity, identity, and development workflows. Payment processing may be handled by external payment processors. AnalysisPlace does not intentionally share customer document content with third parties for advertising, resale, or unrelated purposes.
Vendor and partner risks are reviewed periodically. New vendors that may access sensitive data are reviewed for security posture, data access scope, business purpose, contractual requirements, and risk before approval.
Sometimes. Where direct transfer is available, document content is processed on the user’s device and is not uploaded to AnalysisPlace. Where cloud transfer or cloud document processing is used, document content may be temporarily uploaded and is automatically deleted according to documented retention rules.
No. AnalysisPlace does not train AI models on customer document content or customer personal data.
No. AnalysisPlace does not sell, rent, or lease customer lists or customer personal data.
Production access is restricted to authorized AnalysisPlace personnel with a business need. Administrative access is protected using unique accounts, least privilege principles, and multi-factor authentication.
Yes. Data is encrypted in transit using HTTPS/TLS and encrypted at rest using Microsoft Azure-managed encryption capabilities.
Yes. Customers may review the public Microsoft 365 Certification listing linked above.
| Review topic | Where to look |
|---|---|
| Microsoft 365 Certification | See the Microsoft 365 Certification section and Microsoft public listing. |
| Privacy policy | AnalysisPlace Privacy Policy |
| Terms of use | AnalysisPlace Terms of Use |
| Data transfer method | Content Uploading and Content Transfer Method |
| Data types and retention | See Types of Data Processed and Data Retention and Deletion. |
| Encryption | See Encryption. |
| Access controls | See Access Control and Administrative Security. |
| Development and deployment controls | See Secure Software Development and Change Control. |
| Vulnerability management | See Patch Management and Vulnerability Management. |
| Incident response | See Incident Response. |
| Business continuity and disaster recovery | See Business Continuity and Disaster Recovery. |
Customers with additional questions may contact AnalysisPlace through the published contact process. For security reviews that require non-public operational evidence, AnalysisPlace may provide additional information under an appropriate confidentiality arrangement.