Security & privacy
Your workbooks are the most sensitive thing you own
So we built SheetDelta to touch them as little as possible. Most of what we do never leaves your device at all, and where it does, you decide exactly how much.
What happens to your files, by surface
Pick the surface whose trust posture matches the workbook in front of you.
| Free web tool | CLI | Excel add-in | Hosted platform | Self-hosted | |
|---|---|---|---|---|---|
| Where files are processed | Your browser | Your machine | Your device | Our servers | Your network |
| Files leave your control | Never | Never | Never (free mode) | Only files you connect | Never |
| Stored at rest by us | No | No | No | Encrypted; retention you set | No; your storage |
| Account required | No | No | No | Yes | Yes |
| Usable air-gapped | Comparing only | — |
“Never (free mode)” for the add-in means signed-out, local comparing. Signed in, the pane sends the open workbook to the platform to run your team’s control checks, and again when you submit a version for review; the check stores nothing, a submitted version is kept.
The questions a security team asks
Straight answers, not a generic trust page.
- Are files uploaded, or processed locally?
- The web tool and the free add-in process everything locally, in your browser or in Excel. The CLI is fully offline: it makes no network calls at all. Only the hosted platform processes files on our servers, and only the files you explicitly connect.
- Are files stored?
- Not by the local surfaces. On the hosted platform, connected versions are stored encrypted so you can compare and review them, with retention you control.
- Can we control or disable retention?
- Yes. Hosted customers set how long versions and comparisons are kept; Business plans add stricter retention controls and legal-hold options.
- Is there an offline / CLI option?
- Yes. The CLI runs with no network access whatsoever, so it works air-gapped and in locked-down CI. It is built for CI and scripted comparisons.
- Can teams self-host?
- Yes. The whole platform can run inside your own network, including fully air-gapped, on an annual contract.
- What is logged?
- The local tools keep no logs of your file contents. The platform logs the metadata it needs to run the audit trail (who changed and approved what, and when), never the values of cells you didn’t connect.
- Where does the Excel add-in come from?
- Microsoft AppSource. It is a listed Office add-in, offer WA200012038, published by Flamingo Research & Development, so Microsoft ran it against its Office Add-in validation policies before it went up, and it updates through the store like any other. A Microsoft 365 admin can also deploy it centrally from Integrated apps, so nobody installs anything themselves.
- Why does the add-in ask for write permission if it never writes?
- Because the alternative fails quietly. The pane makes no document writes: it moves Excel’s own selection to point at a cell, and that is the whole cell-jump story. On some Excel hosts moving the selection sits behind write consent, and an add-in that asked for read-only would lose it with no error. So it declares read/write and we prove it does not use it: an end-to-end test in real Excel fingerprints the workbook (values, formulas, number formats and comments) before and after the pane runs, and compares the two.
- How are workbooks encrypted?
- In transit with TLS 1.3 and at rest with AES-256 on the hosted platform. Self-hosted deployments use your own storage and keys.
What the connector can reach
SheetDelta uses Microsoft Graph’s Sites.Selected
model, so it can reach only the sites your admin has granted and never the rest of your
tenant. Be precise with your own security team about the size of that grant: it is made per
site collection and asks for the full control role on it, which is what lets later library
and file grants happen without elevated scope again. The list of workbooks we watch is a
setting inside that access, not the edge of it. The most sensitive workbooks never need the
cloud at all, which is what the
free in-browser tool
and self-hosting are for.
Frequently asked questions
What permissions do you request on SharePoint?
Sites.Selected model, so it can reach only the sites an admin has granted and never your whole tenant. Two details your security team will want. The grant is made per site collection and asks for the full control role on it, because that is what lets every later library and file grant happen without an elevated scope again. And during the grant session itself the admin’s own delegated Sites.FullControl.All is used to list sites, held in memory for that session and never stored. Which workbooks we watch is our setting within that access rather than the boundary of it. Where is the hosted platform data held?
Do you train any models on our workbooks?
How do we delete our data?
Have a security review to run?
Send us your questionnaire; we would rather answer it up front than surprise you later. Considering self-hosting, or want to talk it through first?