EcoIQ Security, Privacy & Compliance Centre
Protect industrial evidence, personal data, approvals and AI workflows.
EcoIQ Security, Privacy & Compliance Centre provides the governance layer for role-based access, data protection, consent, audit logs, evidence permissions, supplier/funder access, data retention, public reporting controls and AI agent safety. It helps EcoIQ become enterprise-ready for governments, investors, industrial companies, suppliers, Microsoft ecosystem partners and development institutions.
Core purpose: Make EcoIQ secure, permissioned, auditable and compliant-by-design.
Connected EcoIQ Modules
Data Room & Evidence Vault
Enforces the permission levels documented in Data Room Permissions.
API & Integration Layer
Enforces the API keys, scopes and rate limits documented in API Security.
AI Agent Operations Console
Supplies the agent outputs governed by AI Agent Safety & Governance.
Governance & Expert Review Board
Approves the human review decisions this centre tracks.
Public Trust & Impact Portal
Enforces the Public Reporting Controls before publication.
Command Centre
Surfaces security and compliance alerts across the project pipeline.
Mobile / iPad Inspection Mode
Captures the photos and personal data governed by Privacy / PII Protection.
Supplier & Funding Marketplace
Operates within the supplier and funder access scopes defined here.
Institutional Finance Engine
Its financial models are protected under Data Room Permissions.
Sales CRM & Partner Pipeline
Its contact and outreach data falls under Privacy / PII Protection.
Customer Success & Renewal Engine
Its account data is governed by Role-Based Access Control.
Product Analytics & KPI Engine
Its usage data is subject to the same privacy and retention rules.
Microsoft Ecosystem Core Stack
Provides the identity, governance and monitoring building blocks this centre documents.
SharePoint
Enforces evidence pack permissions.
Teams
Delivers access review and approval notifications.
Microsoft Fabric
Stores governed metadata and audit telemetry.
Power BI
Renders security and compliance dashboards.
Dynamics 365
Applies access scopes to customer and partner records.
Presidio-style privacy tooling
Detects PII across documents, images and notes.
Responsible AI tools
Support explainability and governance of AI agent outputs.
Security Domains
Role-Based Access Control
Roles
Permissions should control
Data Room Permissions
Permission levels
Rules
Privacy / PII Protection
Protect
Capabilities
Consent Management
Track consent for
Consent statuses
Audit Logs
Track
Every audit record should include
Data Retention & Deletion
Track
Rules
API Security
Controls
AI Agent Safety & Governance
Track
Rules
Public Reporting Controls
Before publishing, check
Compliance Readiness
Show readiness for
Do not claim formal certification unless actually obtained. Phrase as "compliance-ready controls" or "designed to support".
Dashboard Cards
Security Table Fields
Sensitivity Levels
Data Types
Example Scenarios
Village Clean Heating Pilot
Risk: Household photos and location data may contain personal information.
Controls
- Consent required
- Exact address hidden
- Public summary only
- Before/after photos approved before publication
- Sponsor name shown only if approved
Status: Public reporting blocked until consent is recorded.
Factory Energy Efficiency Memo
Risk: Financial model and production data are commercially sensitive.
Controls
- Investor due diligence permission only
- Supplier cannot view financial model
- Public portal shows only aggregated impact
- Audit log tracks access
Status: Restricted.
Supplier RFQ Pack
Risk: Supplier needs technical specs but should not see investor documents.
Controls
- Supplier pack permission level
- Quote upload only
- No access to finance memo
- No public sharing
Status: Ready for approved supplier outreach.
AI Agent Photo Diagnosis
Risk: AI visual finding may be interpreted as confirmed engineering fact.
Controls
- Label as AI hypothesis
- Requires engineer verification
- Cannot be used in public report until reviewed
Status: Needs verification.
Microsoft Security Integration
- Microsoft Entra ID concept for identity and access
- Microsoft Purview-style data governance concept
- SharePoint permissions for evidence packs
- Teams approvals for human review
- Microsoft Fabric for governed metadata
- Power BI for security dashboards
- Power Automate for access review workflows
- Presidio-style PII detection
- Responsible AI Toolbox for explainability and governance
- Azure Monitor / Application Insights concept for logs
- Key Vault concept for secrets and API keys
Use careful wording: "designed to integrate with" or "can use", not "certified by Microsoft".
Amanah Autopilot for Compliance
Amanah Autopilot can run overnight and:
- Detect expired consents
- Flag PII in new documents
- Identify public summaries missing approval
- Detect Data Room packs shared too widely
- Find AI outputs needing human review
- Flag stale evidence
- Prepare access review list
- Generate compliance morning briefing
Morning briefing example: "Overnight, EcoIQ found 3 documents with possible PII, 2 public summaries missing consent, 1 supplier pack shared too broadly and 4 AI outputs requiring human review."
No Harm Gate for Security & Privacy
Before data is shared, published or used externally, check:
- Is the user authorised?
- Is the document permissioned correctly?
- Does the file contain personal data?
- Is consent recorded?
- Is the evidence public-safe?
- Are exact locations safe to show?
- Is supplier/funder access limited?
- Is the AI output approved?
- Is the impact claim MRV-backed?
- Is the audit trail complete?
Safety and Governance
- EcoIQ security controls are platform governance features and do not replace formal legal, compliance, cybersecurity or data protection review.
- Do not claim certification unless obtained.
- Sensitive data must be permissioned, audited and protected.
- Public reporting requires consent, MRV evidence and human approval.
- AI outputs require review before high-impact use.
- Maqasid/Mizan is ethical decision-support, not a fatwa.