The evidence never leaves your tenant.
Most ISMS platforms ask your auditor to trust them. Certaria asks your auditor to read your evidence. Because Certaria installs into your own Microsoft tenant, your audit trail is rows in your own Dataverse, not a dashboard in our cloud. Your auditor verifies the same data you do, under the same Microsoft access controls. The platform never holds your evidence. It cannot. By design.
Screenshot capture pending: a control row open in the maker portal, evidence reference text visible.
The meta-audit problem
Most ISMS platforms ask your auditor to verify two things: your controls, and the platform itself. That is a meta-audit. It is slow, it is expensive, and your auditor does not enjoy it. When the evidence lives in a vendor's cloud, the vendor's dashboard becomes part of your audit scope, and a SOC 2 attestation stands in for the evidence your assessor actually wants to read. Certaria removes the second job.
Five structural answers
Each claim below is an architectural decision, not a policy promise. Each comes with the artefact your auditor inspects to verify it.
The platform installs into your own Microsoft tenant. No vendor cloud.
Certaria deploys as a managed solution inside your Microsoft 365 environment. There is no Talastron-hosted service holding your records, which means the Microsoft compliance baseline your auditor already relies on covers the platform layer automatically.
Screenshot capture pending: Power Platform admin centre, Certaria managed solution in the customer environment.
What your auditor sees: The Power Platform admin centre in your tenant, showing Certaria installed as a managed solution in your environment. Your administrator can show this in one click.
Your audit trail is human-readable text in your own Dataverse rows. No proprietary tokens.
Every evidence claim Certaria records is stored as plain text on the control record itself: what was verified, when, and by which mechanism. An assessor reads the row. There is no encoding to decode and no vendor export format standing between the evidence and the person verifying it.
Screenshot capture pending: Dataverse control row with evidence reference text visible (customer name anonymised).
What your auditor sees: A control record open in your environment with the evidence reference text visible, reading like a sentence: which policy was verified, on what date, by which scan.
Recurring scans use Microsoft Graph with application permissions. One step from API call to evidence row.
The Readiness Scan reads your security posture through Microsoft Graph, the same documented API Microsoft publishes for everyone, under permissions your administrator consented to once. Each scan writes its results to rows in your environment. The trace from API call to stored evidence is one step, and both ends are visible to your auditor.
Screenshot capture pending: the Graph call paired with the Dataverse row that received the result.
What your auditor sees: The Graph call and the Dataverse row it produced, side by side. The demonstration in the next section shows exactly this.
Credentials, configuration and evidence live in three separate layers. Each is independently verifiable.
Authentication credentials live in Microsoft’s connection store, never in Certaria’s data. Configuration metadata lives in environment variables your administrator can inspect. Evidence data lives in your Dataverse rows. Talastron sees none of the three. There is no backdoor, and nothing to extract, because nothing was ever exfiltrated.
Auth
Configuration
Evidence
What your auditor sees: Three screens, three boundaries: the connection reference (auth), the environment variable list (configuration), and a Dataverse evidence row (data).
The platform monitors itself, and the log is append only.
Certaria writes its own health checks to a chronological log in your environment, retained for 90 days and visible to your administrator. If a scheduled scan fails, the failure is recorded and your administrator is told, loudly. A platform that hides its own failures is not an evidence system.
Screenshot capture pending: health check table view with chronological entries.
What your auditor sees: The health check table in your environment, showing chronological entries your administrator can filter and export like any other record.
One step, both ends visible
This is the demonstration that closes the meta-audit question. On the left, the Microsoft Graph call that reads your security posture. On the right, the Dataverse row in your tenant where the result landed.
Screenshot capture pending: the Graph call paired with the Dataverse row that received the result.
Your auditor verifies the platform in one step. The Graph call returns the evidence. The Dataverse row stores it. Both visible to your auditor, in your own tenant.
Send this to your assessor before Stage 2
The Certaria Auditor's Guide explains the evidence model in audit language: what to open, what to look for, and how to trace a claim from Graph call to Dataverse row. Share it with your certification body before you buy, and de-risk the platform choice entirely.
Download the Auditor's Guide (PDF, 4 pages)No email required.
The honest limit
Microsoft's compliance baseline covers the platform layer: Power Platform, Dataverse, Entra ID and Microsoft Graph. Certaria sits on top of that baseline and inherits it. What Certaria does not do: replace your need for a competent ISMS owner, automate decisions that ISO 27001 explicitly reserves for human judgement, or remove your need for an external auditor. We are the evidence system. The accountability is still yours.