Security and governance

How DocLoq keeps external sharing governed

DocLoq adds control around the external-sharing workflow while keeping documents in Microsoft 365. The goal is a governed path for the business, not a parallel file-sharing stack.

Trust architecture

Layered controls around tenant content

DocLoq adds identity, policy, and audit layers around documents that remain in Microsoft 365. Each layer is observable and operable by your admins.

1

Your Microsoft 365 tenant

SharePoint, OneDrive, Teams. Documents stay where they live.

2

Identity boundary

Internal users via Microsoft Entra ID. External recipients verify through OTP or federated access.

3

Policy and protection

View-only, watermark, expiry, download controls — applied before delivery.

4

Audit and revocation

Workflow-grouped activity. Revoke access at any time.

Documents never leave your tenant. The control layers wrap around the existing Microsoft 365 boundary, not in front of it.

Risks and controls

What goes wrong, and what DocLoq does about it

External sharing fails in predictable ways. Each control is paired with the specific risk it removes.

Risk

Oversharing by default

Anyone-with-the-link sharing and inherited permissions make access too broad and hard to audit later.

Control

Identity-bound shares only

Every share is tied to a verified recipient. No anonymous links, no inherited surprises.

Risk

Unmanaged guest lifecycle

External collaborators can accumulate as guest identities that nobody owns or removes.

Control

Right access model per share

OTP access avoids unnecessary guest setup for quick shares. Federated login can use Entra policies when Conditional Access, MFA, or governance requires it.

Risk

Control breaks at delivery

“View only” is easy to bypass with downloads, screenshots, and forwarded files.

Control

Policy applied at runtime

Watermarking, view-only, expiry, and download rules are enforced inside the controlled viewer.

Risk

Fragmented audit

Activity is spread across SharePoint, Teams, Entra, and Purview — never aligned with a single share.

Control

Workflow-grouped audit

Every event sits under the share it belongs to. Revocation is one action, not a chase.

Security posture

What security and compliance teams should expect

  • Built on Microsoft 365 boundaries

    DocLoq is designed to work alongside SharePoint, OneDrive, Microsoft Entra ID, and Microsoft Purview rather than replacing them.

  • Least-privilege external access

    The default posture is controlled, time-bound access. Broader permissions are explicit decisions tied to the workflow.

  • Operational visibility

    Sharing events are grouped around the actual external-sharing use case, which is easier to review than reconstructing activity from multiple disconnected tools.

Security review

Information typically needed during evaluation

Bring these to the first security conversation. We will respond with specifics, not adjectives.

  1. 01

    Data handling scope

    What stays in the tenant, what metadata the service holds, and which operational components participate in the sharing flow.

  2. 02

    Deployment and support model

    How the product is introduced, which controls are available on day one, and how issues are routed during evaluation and rollout.

  3. 03

    Procurement and trust follow-up

    Subprocessors, incident contacts, architecture questions, and evidence can be reviewed as part of the commercial discussion.

Need a security walkthrough?

Bring your security, IT, or procurement stakeholders to the first conversation and we will walk through the control model directly.