Egress manifest
Every host the service may reach, with its purpose and direction, and how the list is enforced: one egress client, a log of every call, and your firewall.
Updated 2026-09-22
Each installation generates its own egress manifest from its configuration, with your own host names in it, and the runbook and the data statement are generated from the same file. This page is the standard list: every host an installation reaches, what it is for and which way the data moves.
The hosts
| Host | What it is for | Data |
|---|---|---|
| Microsoft Graph | Attorney mail and attachments from the one shared mailbox, read by delta synchronisation; the morning digest sent from that mailbox; the loan summaries, the portfolio workbook and the policy file in the one SharePoint library | In and out, under the scopes on the data statement |
| Microsoft Entra ID sign-in | Tokens for the service's own managed identity | Tokens only |
| Your feed locations | The MSP or Sagent extracts, the AACER match file and the attorney portal's status export, pulled from where you already receive them | In |
| Your servicing system | ICE MSP through your own Interchange and DIS access, or Sagent through its APIs: task and field state read, extended deadlines, holds, re-projections, loan-history notes and tasks written | In and out |
| Your claims tool | ICE Claims or Cloud-Claims: the claim record imported at conveyance or CWCOT title, the merged claim written back | In and out |
| Your imaging system | The imaging export for loans in default in; the documentation bundle and the claim-file manifest filed to the loan's folder | In and out |
| The Proxara bundle endpoint | The signed court-record bundle, the signed reference bundle and signed releases | In, pulled; nothing is sent but the request |
The reader is on none of these. It reaches only the private endpoints inside your tenant and the Azure monitoring service tag.
How the list is enforced
A name in the manifest is a claim; the client, the log and the customer's firewall are the enforcement.
- Network security groups cannot filter by host name, so the service's subnet allows HTTPS out and the list is enforced in the service: one egress client, with the host list compiled in, which refuses any other host. The image carries no other network client.
- Every outbound call is logged with its host.
- Where you run a network firewall, the installer takes a route table that sends the subnet's outbound traffic through it, so your perimeter enforces the same list.
- The reader's subnet has no route to the internet at all.
How it is tested
The acceptance tests check all three in a clean subscription: a connection from the reader to any internet host fails; a call from the service to any host outside the manifest is refused by its egress client and logged; each host in the manifest succeeds.