Security & Compliance First.
Your email data is your company's most sensitive asset. Mailarch is built with zero-trust principles, multi-cloud air-gapped data resilience, and strict jurisdictional compliance.
Encryption at Rest & Transit
All archived attachments are encrypted with AES-256 at rest and TLS 1.3 in transit between Microsoft Graph API, Mailarch processing engines, and sovereign object storage — end-to-end.
Off-Tenant Air-Gapped Resilience
Air-gapped from your primary Microsoft 365 identity boundary in sovereign cloud storage with Retention Policy Lock enabled. Maintaining an off-tenant immutable archive protects against single-vendor ransomware or tenant compromise. SEC Rule 17a-4 & CFTC WORM compliant.
Tenant Data Isolation
Each customer's data is stored in logically isolated storage paths with per-tenant encryption keys. Cross-tenant data access is architecturally impossible — not just policy-guarded.
Microsoft Entra ID SSO
Attachment download links authenticate users via Microsoft Entra ID (Azure AD) single sign-on. No separate passwords or account creation. If a user leaves the organization and their Entra account is disabled, download access is immediately revoked.
Bring Your Own Storage (BYOS)
For Enterprise customers & strict Microsoft environments, Mailarch supports Bring Your Own Storage (BYOS). Provision an Azure Blob container in your own Azure subscription, keeping 100% of archived files inside your Azure tenant while drawing down Microsoft Azure commitments (MACC).
Audit Trail & Logging
Every attachment extraction, download, and modification is logged with message ID, timestamp, user identity, file hash, and storage URI. Full audit trail available for compliance reviews, legal discovery, or internal security audits.
Compliance & Data Sovereignty
Meeting the strict requirements your legal and InfoSec teams care about.
🇪🇺 GDPR & UK Data Protection
Mailarch operates under UK GDPR / Data Protection Act 2018, which holds full adequacy status with the EU GDPR. Data transfers between UK infrastructure and EU customer tenants require no additional Standard Contractual Clauses (SCCs).
Standard Data Processing Agreements (DPA) are available for all business plans, with custom sub-processor schedules for Enterprise contracts.
🌍 Strict Data Residency
Select your preferred sovereign data residency region to satisfy 95%+ of InfoSec audits out of the box:
- ✓ London: europe-west2 (UK GDPR Jurisdiction)
- ✓ Frankfurt: europe-west3 (EU GDPR Jurisdiction)
- ✓ Iowa: us-central1 (US Data Sovereignty)
- ✓ Enterprise BYOS: Any Azure Blob / GCS region in your own cloud subscription
📐 SOC 2 & Hyperscaler Security
Mailarch infrastructure runs on SOC 1/2/3, ISO 27001, ISO 27017, and ISO 27018 certified hyperscaler infrastructure. Our application layer adheres to SOC 2 Type II control frameworks with formal audit certification readiness.
⚖️ Litigation Hold & Purview Awareness
Before processing any mailbox, Mailarch queries Microsoft Purview retention policies and litigation holds via Graph API. If detected, the admin is alerted and can skip that mailbox. Original .eml copies are always preserved in WORM-locked storage regardless.
Permission Details
Exactly what Mailarch requests and why.
| Permission | Type | Phase | Purpose |
|---|---|---|---|
Reports.Read.All |
Application | Read-Only Scan | Fetch tenant-wide mailbox storage metrics, quota caps, and item counts |
Mail.ReadWrite |
Application | Scan & Cleanup Execution | Query email metadata, extract heavy attachments, and update email body with secure download links |
User.Read.All |
Application | Both | List active users, email addresses, and license assignments |
All permissions use the OAuth 2.0 Client Credentials grant (service-to-service). No individual user login sessions are created.