Security
How access is controlled
Clafk holds an authorisation to access a customer's connected mailbox. The controls below describe how that access is protected.
Authentication & authorization
Mailbox access begins with an explicit grant from an authorised user, and can be withdrawn at any time.
- Access is granted through OAuth with Google or Microsoft. Clafk never receives or stores a mailbox password.
- For Gmail, Clafk uses Google’s restricted gmail.modify permission to read and modify the mailbox data the service needs. Clafk does not request the Gmail send scope.
- As a product boundary, Clafk does not send email on the user’s behalf and does not delete customer email on the user’s behalf.
- Access can be withdrawn in Clafk or in the mail provider’s own settings. Revoking access prevents Clafk from continuing to access that mailbox.
- Google Workspace and Microsoft 365 administrators can allow or block Clafk for their organisation.
The permissions requested from each provider are listed in the documentation: Gmail and Microsoft.
Database access controls
Customer data access is restricted using account-scoped access controls.
Internal services operate with the minimum access they require, and privileged operations are scoped to the signed-in user’s own records.
Credential handling
Provider credentials are handled in protected server-side systems and are not exposed to the browser.
- A mailbox authorisation is used only to access the mailbox the user authorised, and is not exposed to end users or to code running in the browser.
- It is removed when a mailbox is disconnected.
Customer isolation
Customer data is logically isolated by account, and access is limited to authorised records.
Mail content is not shared between Clafk customers.
Administrative access
Email processing is automated, and normal operation does not involve human access to mailbox content.
Clafk’s internal administrative tools are designed around operational metadata and do not expose customer email content during normal operation. Access to production systems is restricted to authorised personnel based on operational need, and everyone with such access is subject to confidentiality obligations.
Application security
Controls applied at the application and transport layers.
Encrypted connections
Provider notifications
Diagnostics and monitoring
Clafk reviews and improves these measures periodically.
Incident response
Clafk notifies affected customers without undue delay after becoming aware of a personal data breach.
Clafk provides the information reasonably available to help the customer meet its own obligations.
Vulnerability reporting
Clafk welcomes reports from security researchers and customer security teams.
Send a description of the issue, how to reproduce it, and the impact you believe it has. Please do not access, modify, or retain data belonging to anyone other than yourself while investigating.
Last updated 3 August 2026. These measures are set out in the Clafk Data Processing Agreement.