{
  "slug": "microsoft-visio",
  "category": "diagrams",
  "name": "Microsoft Visio",
  "description": "Microsoft's diagramming app for flowcharts, org charts, floor plans and network diagrams, available as a Windows desktop app and in the browser as part of Microsoft 365. Cloud files are stored in OneDrive or SharePoint.",
  "website": "https://www.microsoft.com/en-us/microsoft-365/visio",
  "license": null,
  "platforms": [
    "windows",
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 56,
  "coverage": 100,
  "summary": "Microsoft Visio scores 56 out of 100 (grade D) on the diagrams and whiteboards criteria. It meets 5 of 8 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration and security headers. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/diagrams/microsoft-visio/",
  "markdown": "https://privacyratings.com/diagrams/microsoft-visio/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://learn.microsoft.com/en-us/microsoft-365-apps/privacy/required-diagnostic-data",
      "note": "Visio, like other Microsoft 365 apps, always sends required diagnostic data to Microsoft, which cannot be turned off."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
      "note": "Sold by subscription with no ads in Visio, and the privacy statement says personal files and documents are not used to target ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
      "note": "Microsoft 365 services have SOC 2 audits by an independent CPA firm. The reports are only available to customers through the Service Trust Portal."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
      "note": "Publishes counts of government requests for consumer and enterprise data twice a year."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
      "note": "Microsoft notifies users and enterprise customers of requests for their data unless legally prohibited."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=m365.cloud.microsoft&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=m365.cloud.microsoft",
      "note": "Grade A+ (110/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:21:28.061Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}