Forum Discussion
Security validation for Certified Custom Visuals (ProfitBase Financial Reporting)
We are using the ProfitBase Financial Reporting visual in a production environment. The client is concerned about data exfiltration risks associated with third-party visuals. As this is a PBI Certified Visual, could anyone let us know if the visual:
- Does not transmit data to external servers.
- Complies with Microsoft's "no outbound connectivity" rule for certification.
This will help us clear a security audit for our client. Thanks!
2 Replies
- Juan-Power-biSuper User
Hello
Yes both of those are hard requirements for Power BI certification.
Microsoft's certification criteria explicitly states that certified visuals must not access external services or resources. That means no outbound network calls, no data sent to external servers, nothing leaving the browser sandbox. If a visual violates this, it can't get certified - masonreed11tAdvocate II
Since it’s a Power BI Certified Visual, it should meet Microsoft’s certification requirements, including the no outbound connectivity rule. For audit purposes, I’d still get a written confirmation from ProfitBase that the visual does not transmit data externally, as certification alone may not satisfy every security review.