Security & Deployment Model

How FulcrumFOCI handles your most sensitive compliance data

Bring Your Own Tenant (BYOT)

FulcrumFOCI deploys as a managed Power Platform solution into your existing Microsoft tenant — Azure Government or GCC High. All application logic, all data, and all documents reside within your organization's boundary. Fulcrum Advisory does not provision, access, or operate shared infrastructure on your behalf.

No data leaves your tenant

Your ECP content, visitor records, inspection findings, changed condition logs, and compliance documents are stored in your Dataverse environment and SharePoint instance. Fulcrum Advisory support personnel access your environment only with explicit authorization and leave an audit trail via your Microsoft 365 activity logs.

CMMC boundary compatibility

Because FulcrumFOCI runs inside your GCC High tenant, it sits within your existing CMMC authorization boundary. Adding FulcrumFOCI to your SSP requires documenting the Power Platform environment and Dataverse configuration — the same process you follow for any new system component. We provide SSP amendment guidance as part of deployment.

Managed enclave option

For organizations that prefer not to deploy into an existing tenant, Fulcrum can provision a dedicated Azure Government Power Platform environment for FulcrumFOCI. This enclave is customer-specific — no shared infrastructure with other FulcrumFOCI customers.

Solution packaging

FulcrumFOCI is delivered as a versioned managed solution — the same packaging model used for enterprise Power Platform deployments. Updates are applied as new managed solution imports. Customer-specific configurations (tenant-specific IDs, custom workflows) are maintained in a separate unmanaged layer and are never overwritten by updates.

← Back to FulcrumFOCI    Questions? Email us