Vigia is a web app that reads Microsoft Dynamics 365 Business Central from the user's phone. This page states exactly which data is read, where it goes, and what stays on the device.
The app queries Microsoft directly from the user's browser, with that user's own token.
Enough to check that your subscription is active: tenant identifier, subscriber address, plan. The exact list is in section 06.
The extension exposes read queries only, and the app issues read calls only.
No analytics, no advertising cookie. Vigia does not read the device's contacts, location or files.
The data Vigia shows is your Business Central data. It stays under your responsibility and under the control of your Microsoft permissions.
It decides who installs the extension, which accounts use it and which Business Central permissions they hold. Those permissions determine what each user can see.
Keystone publishes the app and the extension. Keystone holds no credentials to your environment: the app holds no secret, each user authenticates on their own Microsoft tenant. No data from your Business Central reaches Keystone. To check your subscription, Keystone does however keep a few identification details, listed in section 06.
Authentication and data are handled by Microsoft services, under the contractual commitments that already bind you to Microsoft for Business Central.
This document describes how the app works technically. It does not replace the assessment your data protection officer may want to carry out.
Vigia reads management aggregates and detail lines: companies, customers, sales and purchase orders, invoices, aged balances, value entries, payment terms, dimensions, budgets, bank accounts. The full list of queries is on the help page.
Management data: amounts, dates, document numbers, dimension codes.
The name of an individual customer, the name of a salesperson, a company name carrying a family name. Vigia adds nothing to what your ERP already holds.
Vigia uses no analytics, no advertising cookie, no tracker. It does not read the device's contacts, location or files.
The extension only exposes read queries and the app only issues read calls. The account used holds the D365 READ permission set.
Four items are written to the browser's local storage. They are sent to nobody.
It avoids signing in again at every launch. Signing out deletes it.
The figures of the last load, to show the screen without waiting. Signing out clears it, so does changing environment.
Thresholds, colour bands, targets by company, group name, logos, language.
Forecast dates and outflow lines you enter yourself. They never go back to Business Central.
Two services run by Keystone come into play. Neither one carries your management data.
On opening, the app asks vigia-saas.key-stone.workers.dev whether your subscription is active. That call carries your Microsoft tenant identifier, nothing else. The answer is kept in the browser for five minutes.
With no Microsoft sign-in, the app opens a demo. It goes through a relay hosted by Keystone, at cockpit-bc-api.key-stone.workers.dev. That relay queries a Microsoft demonstration environment, with fictitious data. It never sees a customer's data, and keeps none.
Vigia keeps no management data. Its application files and its subscription records, however, are hosted somewhere.
The application file is served by Cloudflare Workers. That service distributes code, not management data.
Hosted by Cloudflare, in a storage space reserved to Keystone. Per subscription: the subscription identifier, the plan name and identifier, the quantity, the status, your Microsoft Entra tenant identifier and the subscriber's email address. Nothing else. These records are replicated across Cloudflare's global network and deleted within thirty days of the subscription ending.
Hosted by Netlify.
It stays with Microsoft, in your company's Business Central environment, and on the user's device. It never travels through Keystone.
For data coming from your Business Central, the controller is your company: access, rectification or erasure requests are handled on your side, in the ERP. For the subscription records listed in section 06, Keystone acts as processor and answers within one month: write to contact@key-stone.fr. Same address for any question about the app itself, or about the data you send Keystone through the site contact form.
SASU with a share capital of 100 euros, Bordeaux trade register 908 427 644. Registered office: 14 cours Balguerie Stuttenberg, 33300 Bordeaux, France.
contact@key-stone.fr
Vigia, a reporting app for Microsoft Dynamics 365 Business Central.
This page changes when the app's behaviour changes. The version date is at the end of the page.
Version of 3 September 2026
Keystone answers technical questions about what the app reads and how it connects to your environment.