OpenSlot · Security & IT
Security & IT one-pager
Everything an IT or security reviewer usually asks, in one place: read-only permissions, no calendar data stored, one-click tenant-wide consent, and a standard Outlook add-in you can push to everyone from the Microsoft 365 admin center.
Permissions OpenSlot uses in your organization (all delegated, all read-only)
User.Read (the signed-in user's name/email), Calendars.Read and Calendars.Read.Shared (free/busy for the user and for colleagues whose availability your organization already lets them see), People.Read and User.ReadBasic.All (search colleagues by name — names and email addresses only), offline_access (stay signed in). None of these require admin consent by default, so where your organization lets employees consent to apps, they can use OpenSlot on their own. Many organizations turn that off; then an administrator approves it once, below.
What is and isn't stored
Calendar data: nothing. Free/busy is requested from Microsoft Graph when the user clicks "Find free times", merged in memory, returned, and discarded. For calendars the user can already see in detail, Microsoft includes meeting subjects and locations in that same response; OpenSlot uses only the free/busy string and discards the rest, and never requests event bodies, attendees or attachments.
Stored: the user's email address, plan/billing status (Stripe customer id, status, renewal date), display preferences (timezone, hours, window), usage counts kept against a one-way hash of the email address (including which link or site first brought the account in), and for Team plans the email addresses the purchaser assigns seats to. Sign-in tokens live in an encrypted cookie (web) or an encrypted token in the add-in's own storage — never in a database.
Data flow and processors
Browser/Outlook → OpenSlot (hosted on Vercel, US) → Microsoft Graph. Billing by Stripe (we never see card numbers). Plan/preference records in Upstash Redis. No advertising trackers, no data sales. TLS everywhere.
Approve OpenSlot for your whole organization (one click)
An administrator (Global Administrator, Cloud Application Administrator or Application Administrator) opens this link, signs in, and clicks Accept. It asks for exactly the delegated, read-only permissions listed above and nothing else. From then on every employee can use OpenSlot with no consent prompt:
Link: https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=beeece1c-0b4d-4d25-b7dc-b6e3c261d275&scope=offline_access+https%3A%2F%2Fgraph.microsoft.com%2FUser.Read+https%3A%2F%2Fgraph.microsoft.com%2FCalendars.Read+https%3A%2F%2Fgraph.microsoft.com%2FCalendars.Read.Shared+https%3A%2F%2Fgraph.microsoft.com%2FPeople.Read+https%3A%2F%2Fgraph.microsoft.com%2FUser.ReadBasic.All&redirect_uri=https%3A%2F%2Fuseopenslot.com%2Fapi%2Fauth%2Fcallback%2Fazure-ad&state=admin-consent
If your tenant blocks user consent for third-party apps ("Need admin approval"), this is the fix. Consent can be revoked at any time in Entra → Enterprise applications → OpenSlot. Step by step, for the person who hit the message and the admin who approves it: "Need admin approval" when connecting a scheduling app to Microsoft 365.
Deploy the Outlook add-in to everyone
OpenSlot is listed on the Microsoft Marketplace, so the standard path is: Microsoft 365 admin center → Settings → Integrated apps → Get apps → search "OpenSlot" → choose the users or groups → Deploy.
Prefer to pin the manifest yourself? Integrated apps → Upload custom apps → Office add-in → "Provide link to manifest file":
Either way, the "Insert free times" button appears in their Outlook compose toolbar (web, Windows, Mac, new Outlook) within a few hours, and "Find free times" on every received message.
Billing, seats and cancellation
Individuals: 14-day Pro trial, then Free or Pro ($7/user/month, or $72/year — $6/month). Teams: buy seats in checkout (volume pricing applied automatically: 5–24 seats $5, 25–99 $4, 100+ $3 per user/month; yearly $4/$3/$2), assign them by email on /team, change seat counts, switch monthly/yearly, download invoices, or cancel any time from Manage billing. Card, Apple/Google Pay and US bank debit accepted.
Operational security practices
Architecture: serverless web application on Vercel (AWS, United States) with no long-lived servers or open ports; managed Redis (Upstash, US) reachable only over TLS with a secret token; payments entirely inside Stripe (PCI DSS Level 1). No card data or passwords ever touch our infrastructure, and calendar content is never stored.
Change management: every change is committed to version control, type-checked and unit-tested by a GitHub Actions workflow on every push, and deployed from the main branch; production configuration is managed as environment variables, never in code. Secure coding: OWASP Top 10 practices (input validation and allow-listing on every API route, parameterised/typed data access, no secrets in the client, encrypted tokens, strict TLS).
Vulnerability and patch management: production dependencies are scanned on every push (npm audit in the same workflow), daily against the OSV vulnerability database, and by GitHub Dependabot alerts; findings are risk-ranked by CVSS severity. Patch SLA: critical within 7 days, high within 30 days, others at the next release. Runtime is current Node.js LTS and a supported Next.js release; no unsupported software.
Access control: a single administrative identity with multi-factor authentication on the code repository, hosting/DNS provider, database and payment provider; accounts are provisioned, changed and removed by the owner with a documented checklist. Logging:request and function logs at the hosting provider (≤30 days), Stripe event logs, database access logs — none contain calendar content.
Backup and disaster recovery: application code and configuration live in version control; the only stateful data (plan and preference records) is in a managed database with provider-managed durability, and billing truth is held by Stripe, from which every paid plan can be rebuilt. Recovery is a redeploy from the repository plus environment restore, with a recovery time objective under 1 hour. Incident response: security events are triaged by the owner; confirmed incidents affecting customer data are communicated to affected customers and, where required, regulators without undue delay, with a post-incident write-up. Report security concerns to support@useopenslot.com.
Not held: SOC 2, ISO 27001, HIPAA, FedRAMP. OpenSlot is a small, focused product; we publish these practices rather than claim certifications we do not have.
Self-hosting (regulated organizations)
OpenSlot can run entirely inside your own tenant (your Entra app, your Vercel or container platform, no external database) under a flat annual license. Email support@useopenslot.com.
Contact
Security questions or a questionnaire to fill in: support@useopenslot.com. See also Privacy and Terms. OpenSlot LLC, a Kentucky limited liability company (Organization No. 1623293).