Security & assurance
A practical, evidence-oriented summary of cmail’s upstream capabilities and the work that remains with each deployment. It is not a certification, audit report, or promise that a deployment meets a particular legal or regulatory obligation.
Upstream capability summary
- Personal and shared mailboxes; server-enforced Read, Send as, and Full access delegation; per-user Google or Microsoft OpenID Connect sign-in.
- Inbound handling through Cloudflare Email Routing and outbound delivery through Cloudflare Email Service or Postmark, with D1 metadata and R2 message storage.
- Mail trace and administrative audit views; versioned policy acknowledgement; personal and organisation signatures; configurable retention and quota guardrails.
- Safety controls including HTML sanitisation, executable-attachment blocking, suspicious-link warnings, sender-first-contact notices, and optional spam-score quarantine.
- Guidance for SPF, DKIM, DMARC, MTA-STS, and TLS reporting. These are deployment and transport controls, not an application certification.
Who is responsible for what
| Area | Product | Operator | Provider |
|---|---|---|---|
| Access and administration | Invitation-bound sign-in, server-side delegation checks, sessions, audit and policy controls. | Configure identity clients, invite/offboard people, review access and audit records. | Identity-provider authentication, MFA and conditional-access enforcement. |
| Mail flow and data | Mailbox workflows, storage integration, trace metadata, guardrails and safety presentation. | Own Cloudflare account, D1/R2 backups, retention decisions, routing rules, monitoring and incident response. | Cloudflare routing/storage/runtime availability; outbound provider acceptance and delivery. |
| Domain authentication | Records trusted inbound authentication results when configured and presents operational guidance. | Publish and maintain SPF, DMARC, MTA-STS and TLS-RPT records; validate DNS and reports. | Provider-managed DKIM signing and receiving-provider policy application. |
| Assurance and obligations | Documents supported controls and known limitations. | Determine applicable obligations; obtain independent advice, evidence and assessments where required. | Meet their own contractual, service and compliance commitments. |
Deployment evidence checklist
- Record the upstream commit or release deployed, configuration review date, and responsible operator.
- Confirm isolated Cloudflare resources and secrets for development, staging, and production; test D1/R2 backup and restore.
- Verify OAuth callback URLs, invitation enrolment, least-privilege mailbox access, offboarding, and session revocation.
- Test inbound routing, internal and external delivery, failure paths, attachments, mail trace, and audit events using controlled accounts.
- Verify provider DNS records and controlled-message SPF, DKIM, and aligned DMARC results; monitor TLS-RPT and DMARC reports where enabled.
- Set and test retention, quota, rate-limit, spam-quarantine, notification, and outbound-provider settings appropriate to the organisation.
- Document incident contacts, provider-account access, change control, recovery exercises, and the decision not to use cmail for bulk marketing.
Explicit non-claims
- cmail is not certified against any regulatory, security, privacy, or assurance framework.
- It is not a hosted email service, a managed backup service, or a replacement for operator monitoring and incident response.
- It is not a bulk-marketing or campaign platform and does not provide the related consent, unsubscribe, complaint, reputation, or deliverability controls.
- An in-product audit log is useful operational evidence, not tamper-proof external audit retention.
- Configuring SPF, DKIM, DMARC, MTA-STS, or TLS-RPT does not by itself establish compliance or guarantee delivery.
Current limitations and primary evidence
Read the project materials alongside the source revision you deploy. The email standards and sender requirements explain DNS and sender responsibilities. The current in-product standards page and gap register identifies unavailable capabilities and why. The security policy, security checklist, and deployment and verification guide provide the upstream operating baseline.
The versioned technical source for this summary is docs/assurance.md. The companion privacy and data-handling guide provides an operator data inventory and notice checklist. Use both with the exact source revision deployed when collecting or reviewing evidence.
This page describes the named upstream revision only. Forks, local changes, provider configuration, and deployed versions require their own review and evidence.