Security Assessment & Microsoft 365 Integration for an Internal AI Platform

via Freelancer ·

Budget / Salary20,000–50,000 SGD
TypeFreelance project
LocationRemote
Posted1 hour ago
A higher-education institution is seeking a delivery partner for two related workstreams on an internally-hosted AI chat platform used by its staff and researchers. The work is fixed-price and milestone-based, run with weekly working sessions and a review at each milestone gate.

Workstream 1 — Security assessment and hardening

An independent assessment of the platform, carried out with and reviewed by the client's internal security team, supporting a decision to allow the platform to handle sensitive institutional data. The work covers threat modelling and data-flow documentation, review of identity, access and sharing controls, tooling and egress risk, session and administrative access, and the platform's position relative to the organisation's existing compliance boundary. It concludes with a hardening checklist, low-risk changes applied, and a findings register with severities, remediation and mapping to recognised security standards.

Workstream 2 — Microsoft 365 integration

A first-party Microsoft Graph integration built into the platform, so that content produced in it is saved into, shared through, and discoverable within the organisation's existing Microsoft 365 governance boundary rather than sitting outside it. In scope: persistence to SharePoint, identity-bound and non-public sharing, security-trimmed search over Microsoft 365 content the signed-in user can already access, directory synchronisation from Entra ID, and a unified audit trail across those actions.

The client is seeking a first-party service built into the application — not the deployment of a third-party or end-user MCP server. Token custody and egress control need to remain with the application.

Payment is staged across milestones spanning the two workstreams, with the schedule agreed at award.

To bid, please submit a proposal covering your approach, your indicative pricing and suggested milestone breakdown, and comparable work.

Please note: the detailed scope, architecture, environment and deliverable specification are shared only with shortlisted bidders, under a non-disclosure agreement. There is no access to client systems before award, and bids should be treated as indicative until that material has been reviewed. All deliverables — code, documentation and runbooks — are delivered into client-owned repositories, with intellectual property vesting in the client.
compliance security cloud security microsoft graph microsoft 365 ai development ai integration
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.