Security & privacy
mailvault365 is designed so the answer to "who can see my mail and what gets recorded?" is short, predictable, and verifiable.
Your archive is yours alone. Other customers can never see it, search it, or end up in it.
mailvault365 connects to Microsoft 365 with read-only Graph permissions. We never write to, delete, or modify a mailbox.
Every user sees only their own mailbox by default. Cross-mailbox access is granted explicitly by an admin, per user, per mailbox.
There is no separate password to manage. Everyone signs in via Microsoft 365, so your existing SSO, multi-factor authentication, and conditional-access policies apply automatically — if Microsoft denies the sign-in, mailvault365 denies the session. We don't store your Microsoft password.
When an admin or a user with granted access opens someone else's mailbox, opens a message in it, or downloads an attachment, the action is logged with the user, the timestamp, and the target. Role and access-grant changes are logged the same way. Admins and the account owner review this audit trail under Administration → Activity.
Reading your own mailbox is intentionally not logged — that's day-to-day work, not a compliance event.
Archived emails are stored as standard RFC 822 .eml files from day one — never a proprietary format. Individual messages can be downloaded at any time; on cancellation, contact support and we'll arrange a complete export.
Cancelling stops the billing, not the archive. When a subscription lapses — you cancelled, or an invoice simply didn't go through — your account switches to read-only: everything stays searchable and downloadable. What pauses is the forward-looking work — no new mail is collected, and administrative changes like adding a mailbox or changing who can see what wait until you subscribe again. Nobody should lose a compliance record over a missed payment.
Deleting your data is a separate, deliberate step. When you request account deletion under Administration → Billing, any active subscription is cancelled right away, you're signed out, and a 30-day countdown starts. Change your mind inside that window: sign back in, click cancel deletion, and your archive is still there in full, exactly as you left it. The subscription is not revived with it — it was already cancelled — so the account stays read-only until you start a new one. Once the 30 days are up, a nightly job erases your archived email files from storage and removes your account, users, mailboxes, and audit records from our database.
Backups deserve an honest answer. We take one encrypted backup a night, and it covers the message index — senders, subjects, dates, the opening lines of a message — not the archived email files themselves, which are erased outright. A backup is a sealed snapshot, so we can't reach into it to pull one customer out. Instead of purging them one by one, each backup expires on its own retention cycle and is deleted automatically: most within weeks, the longest-lived within two years.
To operate mailvault365 we rely on a small number of vendors — Microsoft (for the Graph API connection), a hosting provider, a payment provider, and an email-delivery provider. Each is bound by a written agreement and processes data only on our instructions. The current list is available on request.
Found a vulnerability or have a question for our security team? Write to mail@mailvault365.com. We acknowledge reports within one business day.