PPM Compass Logo
PPM Compass 360 For Microsoft 365
For IT & Security Reviewers

Security & Architecture

Where the data lives, what the app can access, and what leaves your tenant.

PPM Compass 360 is a SharePoint Framework (SPFx) web part. It runs in the user's browser and works only with the SharePoint lists of the site it is installed on. Facts on this page refer to version 1.5.0.

⬇ Download the IT Security Fact Sheet (PDF, 2 pages)

1. Architecture

User's browser
Signed in to Microsoft 365. Opens a SharePoint page with the PPM Compass web part.
Your SharePoint site
The web part reads and writes the PPM lists on this site over HTTPS, using the user's own session.
PPM Compass (vendor)
No connection. No server, database or API receives your data.
  • • The app code is inside the .sppkg package and is served from your own App Catalog.
  • • No back end, no external database, no relay or proxy.
  • • Supported hosts: SharePoint pages and full-page apps. It does not need custom script enabled on the site.

2. Permissions

The package requests no Microsoft Graph or Entra ID (Azure AD) API permissions and has no identity of its own. Every request runs as the signed-in user, so the app can never do more than that user can already do in SharePoint.

TaskWhoPermission neededPurpose
Upload the packageITSharePoint Administrator (or App Catalog owner)Standard for any SPFx solution
First setupSite OwnerFull Control on the PPM siteCreates the PPM lists, columns and views
Apply list security (optional)Site OwnerFull Control on the PPM siteSets Members to edit without delete and Visitors to read
Create and edit project dataSite MembersContribute Without Delete on PPM listsDaily work
ViewSite VisitorsReadReporting; financial figures can be hidden from Visitors

Access is managed with SharePoint's standard Owners, Members and Visitors groups. Roles inside the app (for example Project Leader) never change SharePoint permissions.

3. Network & Data

Outbound calls
Only to your SharePoint site. SharePoint itself loads Microsoft's own page assets.
Customer data leaving the tenant
None is sent to PPM Compass or any third party.
Analytics, telemetry, tracking
None in the app. No cookies are set by the app.
AI / LLM services
None called by the app.
Where data is stored
SharePoint lists on your PPM site, with list version history. Retention, backup and eDiscovery follow your Microsoft 365 settings.
In the browser
UI preferences only (language, selected portfolios, saved filters, column widths, zoom), on that device.
Exports
Excel, PowerPoint and PDF files are created in the browser and saved to the user's device, under your own policies.
If you remove the app
Your lists and data stay on the site until you delete them.

4. Third-Party Components

All libraries are bundled into the package. None is downloaded at runtime and none contacts an external service.

  • • Microsoft SharePoint Framework 1.23.2
  • • React 17 and Fluent UI 8 (user interface)
  • • PnPjs 4 (SharePoint REST client)
  • • SheetJS (Excel export)
  • • PptxGenJS (PowerPoint export)
  • • jsPDF (PDF export)

Dependencies are monitored with automated vulnerability alerts. A full component list is available on request.

5. License Check

  • • The license key is a digitally signed text string that a Site Owner pastes into the app.
  • • It is checked in the browser. The app never contacts a license server.
  • • A key is tied to your SharePoint site ID or tenant ID. That ID is the only tenant information we need to issue it.
  • • After a trial or license ends, the app becomes read-only. No data is removed.

6. Deployment & Microsoft Marketplace

How is PPM Compass 360 deployed?

As a standard SPFx package (.sppkg) uploaded to your tenant or site-collection App Catalog. A SharePoint Administrator uploads it; a Site Owner adds the web part to a page and runs the first setup. Updates are new package versions uploaded the same way.

Is it available through Microsoft Marketplace?

Not at the moment. Direct App Catalog deployment is the supported route today. Being listed in the Marketplace is separate from the technical ability to deploy an SPFx solution. Using SPFx does not imply Microsoft endorsement.

7. Privacy Notes for Canadian Organizations

  • • Project data stays in your SharePoint Online tenant, in the Microsoft 365 data location of your tenant (for example Canada).
  • • PPM Compass does not receive, store or process the project or personal data held in your lists, and uses no subprocessors for it.
  • • What we do hold: business contact details you send us (name, email, organization) and the site or tenant ID used to issue your license key.
  • • Your organization stays responsible for its obligations under PIPEDA and provincial privacy laws (such as Québec's Law 25). Because the data stays in your tenant, your existing Microsoft 365 controls apply to it.
  • • The app interface is available in English and German. French language support is planned.

This is technical information, not legal advice. See also our Privacy Policy.

8. Security Contact

Security questions, questionnaires and vulnerability reports: support@ppmcompass.com. Please put "Security" in the subject line. We answer security questionnaires on request. A two-page summary for your security team: IT Security Fact Sheet (PDF).