Resources in your subscription
The storage account uses hierarchical namespace, HTTPS, TLS 1.2, and Microsoft
Entra authentication. Shared-key and anonymous access are disabled. The
standard template enables thirty-day soft deletion for blobs and containers.
Browser CORS permits the General Validation application origin.
The application, API, background services, and application database are operated
by General Validation. They are separate from the execution resources billed to
your Azure subscription.
Who receives access
General Validation’s Azure roles have no customer-storage data permissions.
They do not allow it to read source rows, result artifacts, storage keys, or
customer secrets. Exact-value and evidence reads use customer identities.
Organization membership and Azure storage access are separate. An Owner grants
product access in Organization; a customer Azure administrator controls
storage RBAC and the membership of the optional reader group.