Skip to content
ClafkTrust Center

Security

How access is controlled

Clafk holds an authorisation to access a customer's connected mailbox. The controls below describe how that access is protected.

Authentication & authorization

Mailbox access begins with an explicit grant from an authorised user, and can be withdrawn at any time.

  • Access is granted through OAuth with Google or Microsoft. Clafk never receives or stores a mailbox password.
  • For Gmail, Clafk uses Google’s restricted gmail.modify permission to read and modify the mailbox data the service needs. Clafk does not request the Gmail send scope.
  • As a product boundary, Clafk does not send email on the user’s behalf and does not delete customer email on the user’s behalf.
  • Access can be withdrawn in Clafk or in the mail provider’s own settings. Revoking access prevents Clafk from continuing to access that mailbox.
  • Google Workspace and Microsoft 365 administrators can allow or block Clafk for their organisation.

The permissions requested from each provider are listed in the documentation: Gmail and Microsoft.

Database access controls

Customer data access is restricted using account-scoped access controls.

Internal services operate with the minimum access they require, and privileged operations are scoped to the signed-in user’s own records.

Credential handling

Provider credentials are handled in protected server-side systems and are not exposed to the browser.

  • A mailbox authorisation is used only to access the mailbox the user authorised, and is not exposed to end users or to code running in the browser.
  • It is removed when a mailbox is disconnected.

Customer isolation

Customer data is logically isolated by account, and access is limited to authorised records.

Mail content is not shared between Clafk customers.

Administrative access

Email processing is automated, and normal operation does not involve human access to mailbox content.

Clafk’s internal administrative tools are designed around operational metadata and do not expose customer email content during normal operation. Access to production systems is restricted to authorised personnel based on operational need, and everyone with such access is subject to confidentiality obligations.

Application security

Controls applied at the application and transport layers.

Encrypted connections

Connections to and from the service — including mail providers, AI providers, and infrastructure — are protected using TLS.

Provider notifications

Incoming notifications from mail and payment providers are authenticated before processing.

Diagnostics and monitoring

Diagnostic and monitoring systems are designed to minimise exposure of customer content.

Clafk reviews and improves these measures periodically.

Incident response

Clafk notifies affected customers without undue delay after becoming aware of a personal data breach.

Clafk provides the information reasonably available to help the customer meet its own obligations.

Vulnerability reporting

Clafk welcomes reports from security researchers and customer security teams.

Send a description of the issue, how to reproduce it, and the impact you believe it has. Please do not access, modify, or retain data belonging to anyone other than yourself while investigating.

Last updated 3 August 2026. These measures are set out in the Clafk Data Processing Agreement.