Your data stays where it belongs. In your tenant.
Sightline 365 is a desktop application that speaks directly to your Microsoft 365 tenant over Microsoft Graph. There is no third-party cloud in the middle, no shared review portal, and no telemetry that ships the content of your searches back to us.
Nothing leaves your tenant
Search results, matched files, copied content — all of it stays inside your Microsoft 365 boundary. The destination library is one you already own.
No third-party cloud
Sightline 365 runs on the reviewer's own desktop and calls Microsoft Graph directly. We don't run a middleware server. There's no database, no staging bucket, no proxy.
Microsoft-native auth
Sign-in uses Microsoft OAuth 2.0. Your MFA and Conditional Access policies apply exactly as they do to Outlook or Teams. If your policy says no, Sightline can't either.
Where the bytes actually go.
The picture is simple: the reviewer's desktop app talks to Microsoft Graph, Microsoft Graph talks to your tenant, and the destination is a SharePoint library that you own. No stop-off in between.
Explicitly, so your IT team can tick the box.
Files, emails, and search results never touch a Sightline-owned database or storage account.
Graph requests go from your desktop directly to Microsoft. Nothing runs through a Sightline server first.
Your KQL, filters, and result counts are yours. We don't collect the substance of what you searched for.
No SPFx solution to deploy, no admin app registration to review across every user. The reviewer signs in as themselves.
MFA, Conditional Access, sensitivity labels, DLP — all still apply. Sightline gets exactly the permissions the signed-in user already has.
No S3, no Dropbox, no shared review portal. The destination is a SharePoint library inside your own tenant.
Delegated Graph scopes only.
Sightline 365 requests delegated Microsoft Graph permissions on behalf of the signed-in reviewer — never application-level permissions that would run without a human present. In practice that means the reviewer can only see what they could already see in Outlook, OneDrive, and SharePoint.
- Sites.Read.All · read the SharePoint content the reviewer already has access to
- Files.Read.All · read the files the reviewer already has access to
- Mail.Read · search the mailbox the reviewer is signed in as
- Sites.ReadWrite.All · write into the destination library the reviewer chooses
- User.Read · display the signed-in user's own profile in the app
Ready for IT review.
Point your security team here, then start the 21-day free trial when you're greenlit.