doorcheck
Why DoorcheckHow it worksWho it's forSign in
EN
🇺🇸English🇸🇦العربية🇪🇸Español🇫🇷Français🇩🇪Deutsch🇵🇹Português🇮🇹Italiano🇨🇳中文
Get early access →
Legal

Security & Compliance

Last updated: September 1, 2026

This page summarizes how Doorcheck handles security and compliance so that IT, security, and privacy teams can evaluate the service quickly. For the full data-handling details see the privacy policy; for contractual terms see the terms of service.

Data protection

  • Encryption in transit — all traffic between your mail provider, the Doorcheck console, and our APIs uses TLS.
  • Encryption at rest — stored data, including OAuth refresh tokens and API keys, is encrypted at rest (AES-256-GCM for credentials).
  • Least-privilege access — Doorcheck connects through the provider’s own APIs with the minimum OAuth scopes needed to read, classify, and (in enforce mode) move mail. We never send mail as you, and we are not in your mail flow — no MX changes means disconnecting us can never break mail delivery.
  • Quarantine, not deletion — remediation moves messages to quarantine or a designated folder. Nothing is deleted; release is one click and audit-logged.

Data residency & sovereignty

  • SaaS — your tenant’s data is stored in the region of the deployment you sign up to.
  • Self-hosted / sovereign — Doorcheck can run entirely on your own infrastructure, including the AI models. In that deployment, message content never leaves your environment — suitable for air-gapped and data-residency-constrained organizations.
  • Bring your own AI — operators choose which (if any) cloud LLM provider handles borderline messages, or configure a self-hosted model so no content leaves at all. Cloud providers process content transiently and are contractually barred from training on or retaining it.

GDPR

Doorcheck acts as a data processor on behalf of the organization that connects its mailboxes (the controller):

  • A data processing agreement (DPA) is available on request — contact privacy@doorcheck.io.
  • Data subject rights — access, correction, and deletion requests are honored via the controller; disconnecting a mailbox revokes access and deletes associated message data.
  • Retention limits — quarantined message bodies are purged automatically (30 days by default); verdict metadata is retained to power dashboards and reports.
  • Sub-processors — only those the operator explicitly configures (chosen LLM provider, SIEM destination, reputation lookups), each used strictly to deliver the security features. No advertisers, no data brokers, no sale of data.

Provider program compliance

  • Google API Services — Doorcheck’s use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • Microsoft 365 — access is granted via Microsoft’s consent framework with admin-consented, scoped Graph permissions that you can review and revoke in your tenant at any time.

Operational security

  • Audit trail — every verdict, quarantine, release, purge, and configuration change is recorded in an audit log suitable for compliance review and SIEM export.
  • Visibility — mailbox owners receive their own quarantine digests; operators see fleet-wide posture continuously.
  • Access control — console sign-in supports SSO; multi-tenant deployments isolate each tenant’s data.

Vulnerability disclosure

We welcome good-faith security research. Report vulnerabilities to security@doorcheck.io — we acknowledge reports promptly and keep you informed through remediation. Please avoid accessing other tenants’ data or degrading the service while testing.

Certifications

Doorcheck is in private beta. Formal third-party certifications (such as SOC 2 and ISO 27001) are on our roadmap and not yet issued — we would rather tell you that plainly than imply otherwise. For our current security posture, sub-processor list, or a DPA, email privacy@doorcheck.io.

doorcheck

AI email security that checks the trust behind every message — and purges what doesn't belong before anyone clicks.

Sovereign AI email security.

Platform
Why DoorcheckHow it worksIntegrationsUse casesIndustriesEarly access
Resources
Threat intelligenceGlossaryWho it's forSecurity & compliance
Company
Sign inCareersContact salesSupportReport a vulnerability
Legal
Legal centerPrivacy policyTerms of service
🇺🇸 English🇸🇦 العربية🇪🇸 Español🇫🇷 Français🇩🇪 Deutsch🇵🇹 Português🇮🇹 Italiano🇨🇳 中文
© 2026 Doorcheck — AI email security
Terms of servicePrivacy policy