cmailBack to product page

UPSTREAM ASSURANCE SUMMARY · VERSION 1.0 · 14 AUGUST 2026 · SOURCE REVISION: RECORD THE DEPLOYED COMMIT WITH THIS PAGE

Security & assurance

A practical, evidence-oriented summary of cmail’s upstream capabilities and the work that remains with each deployment. It is not a certification, audit report, or promise that a deployment meets a particular legal or regulatory obligation.

Upstream security policy

Upstream capability summary

Who is responsible for what

AreaProductOperatorProvider
Access and administrationInvitation-bound sign-in, server-side delegation checks, sessions, audit and policy controls.Configure identity clients, invite/offboard people, review access and audit records.Identity-provider authentication, MFA and conditional-access enforcement.
Mail flow and dataMailbox workflows, storage integration, trace metadata, guardrails and safety presentation.Own Cloudflare account, D1/R2 backups, retention decisions, routing rules, monitoring and incident response.Cloudflare routing/storage/runtime availability; outbound provider acceptance and delivery.
Domain authenticationRecords trusted inbound authentication results when configured and presents operational guidance.Publish and maintain SPF, DMARC, MTA-STS and TLS-RPT records; validate DNS and reports.Provider-managed DKIM signing and receiving-provider policy application.
Assurance and obligationsDocuments supported controls and known limitations.Determine applicable obligations; obtain independent advice, evidence and assessments where required.Meet their own contractual, service and compliance commitments.

Deployment evidence checklist

Explicit non-claims

Current limitations and primary evidence

Read the project materials alongside the source revision you deploy. The email standards and sender requirements explain DNS and sender responsibilities. The current in-product standards page and gap register identifies unavailable capabilities and why. The security policy, security checklist, and deployment and verification guide provide the upstream operating baseline.

The versioned technical source for this summary is docs/assurance.md. The companion privacy and data-handling guide provides an operator data inventory and notice checklist. Use both with the exact source revision deployed when collecting or reviewing evidence.

This page describes the named upstream revision only. Forks, local changes, provider configuration, and deployed versions require their own review and evidence.