Security and data
How Mailgestor treats the mailboxes and files it handles.
Read-only access
Every credential Mailgestor holds is read-only. It cannot send, move, label or delete anything in a connected mailbox. Requests are paced under Google's and Microsoft's rate limits so the organisation's own use of the mailbox is undisturbed.
Credentials
OAuth tokens, delegation details and admin consents are encrypted with AES-GCM under a key unique to your account, itself wrapped by a master key held only on the servers. They are never shown in the app, never logged, and never leave the servers. Microsoft refresh tokens rotate on every use.
Archived content
Every message, event and contact is stored once, addressed by the SHA-256 digest of its content, encrypted under your account's key, and never modified. Export files are encrypted at rest and streamed decrypted only to a download that has been authorised.
Rendering
HTML mail is sanitised before it is shown and rendered in a sandboxed frame with no network access, so nothing inside an archived message can call out.
Audit
Every sign-in, connection, job, message read, download and licence purchase is recorded in the account's audit log, which Auditors and above can read and download.
Retention
Exports are deleted seven days after they are built. Archives are deleted six months after their last archive pass, with a week's notice, or sooner on request. Credentials go when the connection is removed, or after six months without a run. Account data goes after the grace period that follows an account deletion request. Billing records are kept for six years as UK tax law requires.
Where it runs
Mailgestor Cloud is hosted in the United Kingdom on infrastructure operated by eNetIdeas Ltd. Payments are through Stripe, which never shares card details with Mailgestor. Transactional email is through Mailgun's EU region. Requests to Google and Microsoft leave from Mailgestor's own addresses.
Backups
The service database is backed up nightly and the encrypted archive store is mirrored, so a failure on Mailgestor's side does not lose a job in progress. Backups do not extend retention: purged content is removed from them on the same schedule.
Reporting a concern
Email [email protected].