Trust and security

A security product has to earn trust, not assume it.

Here is how Quaragate handles your mail, how the system is built, who our subprocessors are, and where we are on formal certification. We would rather tell you exactly where we stand than imply more than is true.

Certifications and frameworks

Where we are today

Quaragate is an early-stage product. We are building toward formal attestation and will publish reports as they are completed. We do not claim certifications we do not hold.

SOC 2 Type II

In progress

ISO 27001

Planned

GDPR and CCPA

Aligned by design

Microsoft 365

App-only, least privilege

Microsoft 365 access

Exactly what we ask Microsoft for

Quaragate connects as a single app you consent to once. It signs in with a certificate, not a shared secret, and it is not in your mail flow, so it cannot delay or drop mail. The default consent screen asks for two Microsoft Graph application permissions and nothing else.

Mail.ReadWrite

Read suspected threats in Junk Email and move messages to quarantine or release them. It does not grant the ability to send mail.

Organization.Read.All

Read your tenant identity once, at onboarding, to confirm the connection landed in the right tenant.

Quarantine release uses an opt-in Exchange Online permission that stays off until you enable it. We never request access to your files, sites, calendars, contacts, chats, or tasks, and you can revoke the grant in Microsoft Entra at any time.

Data handling

How your mail data is treated

  • Purpose-limited access

    Mail is accessed to analyze and remediate threats, nothing else.

  • Per-tenant isolation

    Each tenant's data and verdicts are isolated. One customer's mail is never visible to another.

  • Retention you can reason about

    We retain what is needed to detect threats and keep an audit trail, and can detail retention on request.

  • Revocable at the source

    Access is an app-only grant you can revoke in Microsoft Entra at any time.

Architecture and controls

How the system is built

  • Encryption

    Data is encrypted in transit, and at rest in our infrastructure.

  • Least-privilege access

    Internal access follows least privilege, and the Microsoft grant requests only the scopes it needs.

  • Not in the mail path

    Quaragate is not a gateway, so it cannot delay or drop your mail, and an outage on our side does not stop delivery.

  • Audit trail

    Every state change is recorded, so actions are always accountable.

AI and your email

We do not train AI on your email. Ever.

Quaragate uses AI to classify suspected threats. We never use your email, its content, its metadata, or its attachments to train AI models, ours or anyone else's. The AI provider we use to classify mail processes it only to return a verdict and does not train its models on data sent through its commercial API. Classification is purpose-limited: mail is analyzed to detect and remediate threats, and for nothing else.

Subprocessors

Who helps us run the service

A small, named set of providers helps us run Quaragate. The current list, with regions, is below; we will give reasonable notice of changes to customers under contract.

  • Leaseweb · cloud hosting and database (primary processing, Montreal, Canada)
  • Cloudflare · edge network, DNS, and DDoS protection
  • Anthropic · AI classification of suspected-threat mail (no training on API data)
  • Amazon SES · transactional email (invites and alerts; not your mail content)
  • Stripe · billing (no access to your mail)

Data residency: your mail data and its backups are processed and stored in Canada (Montreal, Quebec). Web traffic to the console passes through Cloudflare's network edge, which may serve requests from outside Canada.

Responsible disclosure

Found something? Tell us.

We welcome coordinated disclosure of security issues. Email [email protected] with details and steps to reproduce, and give us reasonable time to remediate before any public disclosure. We will acknowledge your report and keep you updated.

Document requests

Security questionnaires and, as they are completed, attestation reports are available to evaluating customers under NDA. Start a conversation from the demo page.

Service status is reported at /healthz.