KoalaFix only ever works with the Microsoft 365 access the signed-in person already has. It can never reach anything they couldn't reach themselves. A short list of irreversible actions on your PC is refused outright; anything else that changes your computer pauses for a plain-English yes/no first, with a note on how to undo it. Primary KoalaFix storage is configured in Sydney, while some service and provider processing can occur in other countries.
KoalaFix has two parts: the app on your Windows PC, and a secure KoalaFix server in Sydney. The app does the diagnosing on your machine; the server is what connects to the AI behind the scenes.
What matters for you: none of KoalaFix's own secret keys (the credentials that talk to the AI providers) ever sit on your computer. They stay locked away on the server. The one thing that does live on your machine is your own encrypted sign-in session, protected by Windows' credential store and tied to your account, so it can be shut off by suspending or removing that account. KoalaFix is designed so that a lost or stolen laptop can't be used to extract KoalaFix's keys or impersonate the service.
Everything the agent does is tied to the person who's signed in. It can never do anything in Microsoft 365 that that person couldn't already do themselves.
KoalaFix signs in as the user. It never gets its own master key to your Microsoft 365. It acts with exactly the same permissions the signed-in person already has, and nothing more.
Permissions are approved in two tiers. On first sign-in, every person approves a base set of read-only access plus the everyday permissions needed for diagnostics. Higher-level admin permissions are a separate approval that only your Microsoft 365 Global Admin can give, and they only ever switch on in organisations where that approval has happened.
Everyday access, for every person on first sign-in:
Admin access, only with Global Admin approval:
You can withdraw any of this at any time from the Microsoft 365 admin centre. The moment you do, the agent simply can't perform that action any more, and it tells the user so.
When KoalaFix needs to fix something on your Windows PC, whether that's restarting a stuck service, clearing a cache, or repairing an Office app, it first sorts the action into one of three buckets. That decision happens before anything runs, and it settles whether the action is blocked, needs your OK, or is safe to do on its own.
A deliberately tiny set of irreversible actions KoalaFix will never take on its own. It stops and walks the user through these by hand instead.
Anything that changes your PC but can be undone. KoalaFix pauses and shows a plain-English yes/no that says what it's about to do and how to reverse it. Nothing here happens without your explicit OK.
Read-only checks and a fixed list of known-safe fixes. These run without asking, because they can't harm anything.
When several actions are bundled together, KoalaFix pulls them apart and checks each one on its own. The most cautious result wins, so the design prevents a risky step from being slipped in alongside a safe one.
IT and security teams can ask for the exact, full list of what's blocked, what needs a confirmation, and what runs automatically. We're happy to walk your team through all of it on a call.
KoalaFix installs from a signed Windows installer, signed with a Microsoft-issued certificate, so Windows recognises KoalaFix Pty Ltd as a verified publisher instead of warning you about software from an unknown source.
KoalaFix Solo installs self-serve: download the signed installer, sign in with your own Microsoft account, and approve your own everyday access on first sign-in. There is no admin tier on Solo. The walkthrough below is how business plans install.
Installation is a guided walkthrough call with Oliver, included on every business plan. During that call:
After the call, the rest of your team installs the signed app and signs in with their own work accounts. Each person approves their own everyday access on first sign-in. Larger rollouts receive a scoped installation session so we can map the environment and get KoalaFix ready for the team.
Primary KoalaFix application and database infrastructure is configured in Sydney, Australia. That describes primary storage and relay infrastructure; it does not mean every request, delivery network, support system or provider processing path is in Australia.
Customer-facing chat is processed by Microsoft Azure OpenAI Service / Microsoft Foundry. Azure OpenAI processing may occur in Microsoft data centres outside Australia, depending on deployment configuration. OpenAI remains a separate processor for query embeddings used in knowledge retrieval; it is not a fallback chat provider. Microsoft 365, billing, email, dashboard hosting, crash monitoring, website analytics, security and global delivery services can also process relevant data as described in the Subprocessor List.
Every connection in and out is encrypted in transit. The Privacy Policy explains the categories of data, retention schedule, overseas processing, advertising controls and individual choices.
KoalaFix is not SOC 2 certified today. KoalaFix Pty Ltd was registered on 16 March 2026 and the product is early-stage. We won't display a SOC 2 badge or an "in progress" sticker until we have an auditor's letter to back it up.
If SOC 2 status is a blocker for your procurement team, the installation call is the right place to tell us. We'd rather know early what compliance bar you need.
Security questions, procurement follow-ups, or "our compliance team needs X": email us and we'll get back to you.
Found a security issue? Email support@koalafix.com with “security” in the subject — we triage vulnerability reports within 2 business days.