PathixDataverse Forensics
Security / Compliance
Compliance posture

Two architectural facts
narrow every framework below.

Compliance posture is determined principally by customer-hosted deployment and the metadata-only boundary. Together they narrow the regulatory scope of the platform itself, while preserving your ability to satisfy requirements across your broader environment.

Read the whitepaper (PDF)security@pathix.app
Customer-hosted

Pathix deploys into your Azure subscription from a Bicep template. There is no vendor production infrastructure that processes customer data, so there is no vendor control environment for an auditor to assess in the first place.

Metadata-only

Pathix has no generic Retrieve method and no value, content, or data column. Record bodies have no path into the system, which keeps Pathix outside the scope of the frameworks that attach to record content.

How the metadata-only boundary is enforced →

Framework by framework

Where Pathix sits, and where your environment does the work.

FRAMEWORK
PATHIX POSTURE
SOC 2 Type II
No production hosting infrastructure. Customer Azure subscription provides the SOC 2 control environment.
ISO/IEC 27001:2022
Customer Azure subscription provides ISMS scope.
FedRAMP / Azure Government
There is no vendor cloud to authorize. Pathix deploys into your own Azure subscription, Azure Government included, so the authorization boundary is your tenant's rather than a separate FedRAMP dependency to inherit. License validation is offline and error reporting is customer-initiated, with no phone-home, so Pathix can run in an air-gapped or restricted-network enclave; if AI is enabled it binds to a provider inside your boundary, such as Azure OpenAI Service in Azure Government. Azure Government, GCC High, and DoD impact-level targets are scoped per engagement.
NIST SP 800-53
Pathix inherits your control baseline rather than asserting its own. Running inside your subscription with no vendor production infrastructure, the relevant control families (access control, audit and accountability, system and communications protection) are satisfied by your authorized environment; the read-only, metadata-only boundary limits what Pathix adds to that scope.
GDPR
Pathix holds no business record content, so GDPR data-subject rights against record content do not attach to Pathix. Pathix does store administrative principal identifiers (display names, UPNs), which is personal data, in the customer's own tenant; the customer remains the controller. Pathix-the-vendor receives no personal data.
HIPAA
Pathix does not process PHI. A Business Associate Agreement is not required because Pathix-the-vendor does not receive customer data; Pathix runs in the customer's tenant.
PCI-DSS v4.0
Pathix does not process cardholder data. Out of CDE scope by architecture.
What this page is not

This describes how Pathix's architecture interacts with each framework. It is not a certification, an attestation, or an audit opinion, and it does not certify your environment. Where a row says your subscription provides the control environment, the assessment of that environment remains yours.

Send us the questionnaire.

We will answer it against the actual code paths and the Bicep template, not a marketing summary.

security@pathix.app
Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.