Microsoft Copilot security directory

Scrive eSign

Published by Scrive

Medium risk

Scrive, the Nordic market leader in electronic signatures, offers a comprehensive suite of solutions for document workflows requiring e-signing and identity verification.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
  • Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.

Available capabilities

This add-on exposes 17 tools or capabilities.

  • Add attachment
  • Add new party
  • Append PDF file to main PDF file
  • Cancel a pending document
  • Create document from PDF
  • Create document from template
  • Retrieve document JSON
  • Retrieve document PDF content
  • Retrieve document status
  • Retrieve party status
  • Send reminders
  • Set PDF file for document
  • Start signing process
  • Update document JSON
  • Update party email
  • Update party fields from template
  • Update party properties from template

The interactive security report will load automatically.