Enterprise Security · Zero Body Access

We never read
your email.

Folderwise is the only email triage tool built on a headers-only architecture. Your email body is structurally inaccessible — not just by policy.

0 bytes

of email body stored

TLS 1.3

all data in transit

AES-256

credentials at rest

Compliance & Certifications

SOC 2 Type IIIn Progress · Q3 2026

Annual third-party audit of security, availability, and confidentiality controls. Report available under NDA.

GDPR CompliantActive

Full compliance with EU General Data Protection Regulation. Data processing agreements available.

HIPAA ReadyActive

BAA available for healthcare organizations. No email body content ever stored or processed.

CCPA CompliantActive

Full California Consumer Privacy Act compliance. Data deletion on request within 30 days.

Security Architecture

Headers Only — Never Body

Folderwise reads sender, subject, and date. Your email body is never accessed, transmitted, or stored. Period. This is structural — not a policy.

Copilot & Gemini read your full email body to generate summaries.

Zero Retention

Email metadata is processed in-memory and never persisted beyond the active triage session. After you close your brief, nothing is stored.

Most AI email tools retain message data to improve their models.

TLS 1.3 Encryption

All data in transit is encrypted using TLS 1.3. IMAP credentials are encrypted at rest using AES-256. We never have plaintext access to your password.

Industry standard — but we go further with zero-body architecture.

Admin Audit Log

Every triage action (delete, file, flag) is logged with timestamp, user, and outcome. Exportable as CSV for compliance teams.

Enterprise-grade accountability that Copilot's email features don't offer.

SSO / SAML Support

Native SAML 2.0 and OIDC support for Okta, Azure AD, Google Workspace, and any standard identity provider. IT-approved out of the box.

Required by every enterprise IT department. We ship it, not an add-on.

Data Residency

Choose US or EU data residency. All processing stays within your chosen region. No cross-border data transfers without explicit consent.

Critical for GDPR, HIPAA, and government procurement requirements.

IT Security FAQ

Need a security review?

We offer full architecture documentation, penetration test results, and security questionnaire completion for enterprise procurement. BAA available for HIPAA-covered entities.