AccessPoint — Vendor Questionnaire Answers
The questions vendor-assessment and security questionnaires ask most, pre-answered. If your form asks something not covered here, send it over and we'll complete it.
Vendor: Realizer Services Inc. · Product: AccessPoint · Last reviewed: August 2026
Company
| Question | Answer |
|---|---|
| Legal name | Realizer Services Inc. |
| Founded / headquarters | 2019 · Nova Scotia, Canada |
| Product | AccessPoint — the Microsoft 365-native platform for public-sector access, privacy, and responsible AI. |
| Partnerships | Microsoft Partner; AccessPoint is reviewed and tested by Microsoft as part of the AppSource submission process before listing on the Microsoft commercial marketplace. |
Hosting & data residency
| Question | Answer |
|---|---|
| Where is the application hosted? | In the customer's own Microsoft 365 tenant and Azure subscription. The vendor operates no hosting environment for customer data. |
| Where is customer data stored? | Entirely within the customer's tenant, in the Azure region the customer selects at deployment. Data never leaves the customer's environment. |
| Does the vendor have access to customer data? | No. The vendor has no runtime access to the customer's deployment and holds no copy of customer data. |
| What subprocessors are used? | None. No vendor-side systems store or process customer content. |
| Are there cross-border data transfers? | The product initiates none. Data residency follows the customer's own Microsoft 365 and Azure configuration. |
Security
| Question | Answer |
|---|---|
| Encryption in transit | TLS 1.3. |
| Encryption at rest | Microsoft 365 and Azure platform encryption, within the customer's own environment. |
| Authentication / SSO | Microsoft Entra ID only — no separate accounts or passwords. The customer's MFA and Conditional Access policies apply in full. |
| Authorization | Granular, tenant-configurable role-based access control enforced server-side on every request, plus a PII firewall separating custodians and contributors from requestor and data-subject identity. |
| Audit logging | Every action across every module is written to an append-only, hash-chained audit ledger with integrity verification, exportable as court-ready evidence. |
| Security monitoring | Runs inside the customer's security boundary, so the customer's Microsoft Defender for Cloud, Sentinel, and Purview govern it like any other workload. |
| Hardening defaults | Entra-only database authentication (no SQL credentials exist), Microsoft Defender for SQL on by default, FTPS and basic authentication disabled from first deployment. |
| Software supply-chain integrity | The deployment script verifies the published SHA-256 hash of every artifact and aborts on mismatch. Updates are distributed through the Microsoft marketplace channel and applied on the customer's schedule. |
Compliance
| Question | Answer |
|---|---|
| SOC 2 / ISO 27001 certification? | Not applicable to this deployment model: those certifications attest to how a vendor protects data hosted in its own cloud, and AccessPoint holds no customer data. The equivalent assurance derives from the customer's own Microsoft 365 and Azure environment, which Microsoft certifies extensively. |
| Standards alignment | ITSG-33 control mapping, GC Cloud Guardrails, GDPR Article 30 (built-in ROPA), ISO 31000 (risk register methodology). Detail: government security controls guide. |
| Accessibility | WCAG 2.1 AA is the standard the product and this website are designed against. A self-assessed Accessibility Conformance Report for the application (VPAT® format; static code review, independent adversarial verification, and runtime browser verification, with accessibility linting enforced in CI) is published; a third-party accessibility audit has not yet been performed. See also the accessibility statement. |
AI use
| Question | Answer |
|---|---|
| Does the product use AI? | Only if the customer chooses to deploy the optional AI Assist, which provisions an Azure OpenAI resource in the customer's own subscription and region. Microsoft does not train models on customer content; prompt and response content is never stored; every output is a suggestion a person decides on; a customer-controlled monthly token budget hard-stops all AI processing; and an administrator acknowledges the terms once per tenant, recorded with user and date. |
Continuity, support & exit
| Question | Answer |
|---|---|
| Backup and disaster recovery | All data resides in the customer's Microsoft 365 and Azure environment, so the customer's existing backup and recovery practices apply directly. There is no vendor cloud to recover from. |
| Support | Via realizer.io/support; we respond within one business day. Optional guided setup, training, and consulting are available as services. |
| Data return on exit | A business-readable export of everything is available to the customer at any time, in one click — and the data never left the customer's environment in the first place. How export works. |
| Contract exit | Cancel the marketplace subscription from your Microsoft admin center. Nothing needs to be unwound or repatriated. |