Microsoft Copilot security directory

Legalesign

Published by Legalesign

High risk

Designed for compliance-focused legal and operations teams, Legalesign's connector links Microsoft power platform with the Legalesign eSignature to trigger document and recipient workflows, send reminders, fetch PDFs, and surface form data. Requires an active Legalesign subscription approved for API use.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 25 tools or capabilities.

  • Delete an attachment
  • Download PDF
  • Download the document auditlog
  • Get attachment
  • Get attachments
  • Get document
  • Get document fields
  • Get documents
  • Get groups
  • Get PDF embeddable link
  • Get PDF template
  • Get PDF templates
  • Get recipient
  • Get recipient form fields
  • Get recipient link
  • Get recipient rejection reason
  • Get user
  • Member of a group
  • Members of groups
  • Permanently delete document
  • Send document
  • Send recipient reminder email
  • Upload PDF attachment
  • Upload PDF template

The interactive security report will load automatically.