Skip to content

Security & privacy

Your workbooks are the most sensitive thing you own

So we built SheetDelta to touch them as little as possible. Most of what we do never leaves your device at all, and where it does, you decide exactly how much.

What happens to your files, by surface

Free web tool
CLI
Excel add-in
Hosted platform
Self-hosted
Where files are processed Your browser Your machine Your device Our servers Your network
Files leave your control Never Never Never (free mode) Only files you connect Never
Stored at rest by us No No No Encrypted; retention you set No; your storage
Account required No No No Yes Yes
Usable air-gapped Comparing only —

The questions a security team asks

Straight answers, not a generic trust page.

Are files uploaded, or processed locally?
The web tool and the free add-in process everything locally, in your browser or in Excel. The CLI is fully offline: it makes no network calls at all. Only the hosted platform processes files on our servers, and only the files you explicitly connect.
Are files stored?
Not by the local surfaces. On the hosted platform, connected versions are stored encrypted so you can compare and review them, with retention you control.
Can we control or disable retention?
Yes. Hosted customers set how long versions and comparisons are kept; Business plans add stricter retention controls and legal-hold options.
Is there an offline / CLI option?
Yes. The CLI runs with no network access whatsoever, so it works air-gapped and in locked-down CI. It is built for CI and scripted comparisons.
Can teams self-host?
Yes. The whole platform can run inside your own network, including fully air-gapped, on an annual contract.
What is logged?
The local tools keep no logs of your file contents. The platform logs the metadata it needs to run the audit trail (who changed and approved what, and when), never the values of cells you didn’t connect.
Where does the Excel add-in come from?
Microsoft AppSource. It is a listed Office add-in, offer WA200012038, published by Flamingo Research & Development, so Microsoft ran it against its Office Add-in validation policies before it went up, and it updates through the store like any other. A Microsoft 365 admin can also deploy it centrally from Integrated apps, so nobody installs anything themselves.
Why does the add-in ask for write permission if it never writes?
Because the alternative fails quietly. The pane makes no document writes: it moves Excel’s own selection to point at a cell, and that is the whole cell-jump story. On some Excel hosts moving the selection sits behind write consent, and an add-in that asked for read-only would lose it with no error. So it declares read/write and we prove it does not use it: an end-to-end test in real Excel fingerprints the workbook (values, formulas, number formats and comments) before and after the pane runs, and compares the two.
How are workbooks encrypted?
In transit with TLS 1.3 and at rest with AES-256 on the hosted platform. Self-hosted deployments use your own storage and keys.

What the connector can reach

SheetDelta uses Microsoft Graph’s Sites.Selected model, so it can reach only the sites your admin has granted and never the rest of your tenant. Be precise with your own security team about the size of that grant: it is made per site collection and asks for the full control role on it, which is what lets later library and file grants happen without elevated scope again. The list of workbooks we watch is a setting inside that access, not the edge of it. The most sensitive workbooks never need the cloud at all, which is what the free in-browser tool and self-hosting are for.

Frequently asked questions

What permissions do you request on SharePoint?
Where is the hosted platform data held?
Do you train any models on our workbooks?
How do we delete our data?

Have a security review to run?

Send us your questionnaire; we would rather answer it up front than surprise you later. Considering self-hosting, or want to talk it through first?

Contact security