Security - Profitbase/PowerBI-visuals-Gantt GitHub Wiki
This Security Statement outlines the security architecture and data handling protocols of the Profitbase Gantt Chart visual for Power BI. Because project schedule and resource data are highly sensitive, the visual is built around a strict client-side isolation model to ensure your data remains secure and confidential.
Microsoft Power BI Certification
The Profitbase Gantt visual is Microsoft Certified. To achieve this certification, the visual undergoes rigorous validation and automated code reviews by Microsoft to verify that it adheres to strict security standards:
- No External Network Communication: Certified visuals are blocked from sending data over the internet or connecting to external network services, servers, or APIs.
- Secure Coding Standards: The source code is audited by Microsoft to prevent secure coding vulnerabilities (such as cross-site scripting or data exfiltration).
- High Trust Environments: Because it is certified, the visual can be safely run in highly restricted environments, printed, and exported to PDF/PowerPoint using standard Power BI Service features.
Hosting Model and Data Ingestion
The Gantt visual runs entirely client-side in the user's web browser (or Power BI Desktop) and does not host or transmit your dataset to any external database or Profitbase-owned server.
- Secure Sandbox Isolation: Within the Power BI report canvas, the visual is housed inside a secure HTML5 sandbox called an
iFrame. This sandbox restricts the visual's execution scope, separating it from the rest of your browser environment. - Passive Data Push: The visual operates under a "data push" model. It has no capability to query databases or fetch data on its own. Instead, the Power BI query engine extracts data from your dataset and pushes it directly into the visual to render the chart.

Local Execution and Isolation
All visual operations (such as rendering taskbars, calculating durations, sorting columns, and adjusting timeline zoom levels) are performed locally in the client machine's browser memory. The visual has no access to the hosting operating system's filesystem, local network resources, or external storage devices, ensuring total isolation for your organization's sensitive project data.