Security and privacy
Nothing leaves your infrastructure
The Analyzer runs on your server and talks to exactly three things:
| Direction | Endpoint | Purpose |
|---|---|---|
| Inbound | Soterre → port 4533 | Soterre requesting analyses |
| Outbound | login.microsoftonline.com | Service Principal tokens |
| Outbound | api.powerbi.com | Report export, listings, DAX queries |
There is no telemetry, no callback to Motio, and no licence check against an external endpoint. Report content, findings and capacity data stay between your server, your tenant and your Soterre instance.
Read-only against your tenant
Every call the Analyzer makes to Power BI is a read: listing workspaces, exporting a report, running DAX against a semantic model. It does not publish, modify, delete, refresh or re-assign anything — and holds no credential that would let it.
Report analysis is static. The Analyzer pulls a copy and reads it; it never connects to a running report or executes DAX against your model. The only DAX it ever runs is read-only queries against the Fabric Capacity Metrics model and the INFO.VIEW schema views.
Credentials it holds
| Credential | Stored as | Where |
|---|---|---|
| Service Principal client secrets | Encrypted, via the Data Protection key ring | %ProgramData%\Soterre PBI Analyzer\connections.json |
| Integration token | SHA-256 hash + issue time | integration-token.json |
| Admin Console password | Hashed | admin-credential.json |
| Data Protection keys | DPAPI, machine-scoped | keys\ |
The server is a credential boundary
The key ring is encrypted to the local machine, so any account that can log on to that server can decrypt the stored client secrets. Treat the box as holding tenant credentials in the clear and restrict interactive logon accordingly.
This is also why the Admin Console is loopback-only: anyone who can reach it can add connections and mint integration tokens.
The integration token and the admin password are stored as hashes and cannot be recovered — only rotated or reset.
Network posture
Public API, port 4533. Bound to 0.0.0.0, opened by the installer. The service does not terminate TLS.
Put TLS in front of it
The integration token is a bearer credential: anything that can read the request can replay it. Outside a single trusted subnet, put a reverse proxy with a certificate in front of 4533 and point Soterre at the proxy.
Admin port 5001. Bound to 127.0.0.1. Not a firewall choice you can relax by opening a port — reaching it means a session on the server. Use RDP or an SSH tunnel; do not rebind it to 0.0.0.0.
Authorization
The Analyzer has exactly one caller identity. A valid integration token can do everything the API offers; there are no scopes or roles.
Access control lives in Soterre — who may see which report or capacity is decided by Soterre's user and role model. The Analyzer answers Soterre as a whole, so the integration token is a service credential equivalent to full access to everything the Analyzer holds.
What is stored about your content
Analyses hold findings and metrics — object names, table names, page names, and DAX complexity scores. They are working storage, deleted when Soterre is done with them.
DAX expression text is read to score complexity and is not retained in the result; findings carry a short expression preview.
Capacity history holds item names, workspace names, CU figures, operation counts and user counts — never user identities. It is kept 90 days.
No report data — no rows, no values, no query results from your model — is read or stored at any point. The Analyzer inspects structure.
Backup and disposal
Back up %ProgramData%\Soterre PBI Analyzer\ including keys\ — without the key ring the stored secrets cannot be decrypted. The machine-scoped protection does not travel to a different machine; restoring elsewhere means re-entering client secrets and generating a new token.
Uninstalling leaves that folder in place. Remove it deliberately when decommissioning, and rotate the Service Principal secrets it held.
Supply chain
The analysis engine depends only on the .NET base class library plus SQLite and a bundled native xpress9 decompressor (MIT, compiled from source in-tree). No third-party analysis libraries, and nothing that phones home.