Microsoft Copilot Studio
Microsoft · Agent platform · US · www.microsoft.com/en-us/microsoft-copilot/microsoft-copilot-studio
services/copilot-studio.yamlVendor data-handling terms
“Your prompts (inputs) and Copilot's responses (outputs or results): Are NOT available to other customers. Are NOT used to train or improve any third-party products or services (such as OpenAI models). Are NOT used to train or improve Microsoft AI models, unless your tenant admin opts in to sharing data with us.”
“We don't store or conduct eyes-on review of Copilot inputs and outputs for abuse monitoring purposes. / Customer data, including Copilot inputs and outputs, is stored within the Microsoft Cloud trust boundary.”
“Microsoft might replicate customer data to other regions available within the same geography for data durability. / Note If a tenant's location isn't listed in the data locations table, data is stored in the United States.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| copilotstudio.microsoft.com | app | vendor-documented |
| powerva.microsoft.com | app | vendor-documented |
| api.powerplatform.com | api | vendor-documented |
Assessment
Reasoning: Microsoft's low-code agent builder on Power Platform and Azure OpenAI. No training without tenant opt-in, geography-bound storage with documented exceptions, and admin governance through DLP policies. The agents themselves can reach external services the maker connects.
Flags: No training without tenant opt-in · Geography-bound with documented exceptions · Agents can call external connectors · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Training and storage terms verified against the Power Platform Copilot data security FAQ; data locations against the Copilot Studio documentation.
- 2026-09-16Added with vendor-documented domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.