Product / Knowledge Base / 11. Security and Data Residency

11. Security and Data Residency

User & Administration Guide — Version 1.1.7.0

Guide summary

Customer content stays in the Microsoft 365 tenant. Chronodat does not keep message bodies or attachments on Chronodat servers.

On this page

11.1 Trust boundary

  • Message files and metadata are written with Microsoft Graph to libraries the signed-in user can access.
  • There is no vendor mail store. Chronodat does not persist message bodies or files on Mailroom infrastructure.
  • Delegated Graph only — Office SSO, with MSAL fallback.
  • Licensing PII only — tenant ID, user email, and billing identifiers go to Chronodat and Stripe, not mail content.
  • Telemetry is event names only, such as email_saved. No message content.

11.2 Suggestions are not generative AI

Destination scoring runs in the browser from keywords in the current message. There is no Azure OpenAI or Copilot dependency.

11.3 Compliance notes

  • Retention labels are written to the saved drive item when you supply a published Purview label name.
  • Sensitivity labels inherit from the destination library.
  • Privacy: mailroom.chronodat.com/privacy.html. Terms: mailroom.chronodat.com/terms.html.