Skip to content
ClafkTrust Center

Compliance

Assessments and requirements

The verifications and requirements that apply to Clafk today.

Google OAuth verification

Clafk's Gmail integration operates under Google's API Services User Data Policy.

Google OAuth verification

Approved

Status shown as of 3 August 2026.

Scope
Gmail restricted access (gmail.modify)
Reverification
Required annually
Clafk uses Google’s restricted gmail.modify permission to read and modify the mailbox data the service requires. Clafk does not request the Gmail send scope, and as a product boundary does not send or delete customer email on the user’s behalf. Users can review and revoke access from their Google account, and Workspace administrators can allow or block Clafk for their organisation.

Google’s policy: API Services User Data Policy. The permissions Clafk requests: Gmail permissions.

CASA AL1 security assessment

Required for applications using Google restricted OAuth scopes.

App Defense Alliance CASA AL1

Completed

Assessment details are available from the Clafk Security Team on request.

Assessment
CASA Assurance Level 1
Assessment provider
TAC Security
A security assessment covering Clafk’s use of Google restricted OAuth scopes.

Data protection

Clafk operates as a processor under a written Data Processing Agreement.

  • Clafk is provided by FITIONLED Oy, Business ID 3462861-3, registered in Finland.
  • The customer is the controller of personal data processed through the service; Clafk is the processor.
  • Clafk processes personal data on the customer’s documented instructions, given through the DPA, the Service Terms, and the settings the customer chooses.
  • Clafk assists with data subject requests and data protection impact assessments, so far as reasonable.
  • Clafk notifies the customer without undue delay after becoming aware of a personal data breach.

The agreement itself is on the Legal page.

Microsoft integration

Clafk integrates with Microsoft 365 through Microsoft Graph and uses tenant-controlled OAuth consent. In many tenants an administrator must approve Clafk before a mailbox can be connected, and access can be revoked from Microsoft account settings at any time.

The permissions Clafk requests: Microsoft permissions.

Security documentation

Clafk makes available the information reasonably needed to demonstrate compliance with the DPA.

That includes written answers to security questionnaires, a description of Clafk’s technical and organisational measures, and the published security documentation of its subprocessors. Clafk’s infrastructure is operated by those subprocessors, so Clafk cannot grant access to their premises.

Send a questionnaire

Security reviews, questionnaires, and requests for the DPA go to the Clafk Security Team.

Last updated 3 August 2026.