5.1. Microsoft Service Trust Portal and Privacy Principles
💡 First Principle: Before an organization trusts Microsoft with its data, it reasonably wants evidence — audit reports, certifications, and a clear privacy commitment — so Microsoft publishes this evidence directly, rather than asking customers to simply take security and privacy claims on faith.
Why care: in the shared responsibility model (Phase 2.1.1), the provider's share of security and compliance still needs to be independently verifiable by the customer — you can't audit Microsoft's datacenters yourself, but you can review the evidence Microsoft publishes about them.
⚠️ Common Misconception: Assuming compliance evidence and privacy commitments are the same document. The two subsections below cover a documentation resource and a set of principled commitments, respectively — related, but distinct.