This FAQ covers the most common security, privacy, and compliance questions about Copilot, so you can better understand how it operates, protects data, and fits into your environment.
Data privacy and hosting
Where is my data hosted?
All AI models used for Copilot are hosted on Microsoft Azure OpenAI, which provides enterprise-grade security and regional data sovereignty. North American customers' data is stored in the United States, and European customers' data stays in Europe. Microsoft hosts the OpenAI models in Microsoft's own Azure environment, and the service does not interact with any services operated by OpenAI, such as ChatGPT or the OpenAI API.
Is my data used to train OpenAI, Microsoft, or Atera models?
No. Your prompts (inputs) and completions (outputs), your embeddings, and your training data are not available to other customers, are not used to improve OpenAI models, and are not used to train, retrain, or improve Azure OpenAI Service foundation models. Your data is never shared with OpenAI or Microsoft, and is not used to train any AI models, including Atera's own.
Are customer environments isolated from one another?
Yes. All customer environments are logically isolated within Azure, ensuring no cross-tenant data access. Each customer's knowledge base, scripts, logs, and configurations are logically isolated. For MSPs, data is also segmented per end-customer.
Is data encrypted?
Yes. All data is encrypted both at rest and in transit.
Does Copilot access or crawl local files on end-user devices?
No. Copilot does not crawl, read, or index contents from local files on end-user devices during normal operation, background scans, or support sessions, keeping your environment boundaries intact.
Abuse and content safety
Does Copilot have safeguards to filter harmful or malicious content?
This layer is always on and cannot be disabled, ensuring interactions stay compliant and professional.
Approvals and human-in-the-loop
Is human approval required before Copilot's outputs are used?
Yes. AI-generated content, such as knowledge base articles and script suggestions, is optional and requires manual human admin approval before they're published or executed. No outputs are ever implemented without review.
Need more help?
Have a question not covered here? Contact our support or your Atera account team.