Security and data handling

EWS Bridge performs your application’s calls in memory and keeps only what it needs to run: no message content, ever.

What the bridge stores

  • Your bridge: the e-mail you signed in with, your licence and plan; the licence key sealed with AES-256-GCM.
  • The id of your Microsoft 365 tenant, confirmed by your administrator’s sign-in, and a default mailbox if you set one, sealed with AES-256-GCM.
  • Bridge keys and console sessions as SHA-256 hashes only; a key is shown once.
  • Daily request counters, and coverage events with operation name, status, reason and latency.
  • For synchronisation (SyncFolderItems, SyncFolderHierarchy, notifications): the ids of items in a synchronised folder with Microsoft’s change link, encrypted, for 30 days after the last use.
  • Short-lived caches: Microsoft Graph tokens, mailbox ids (a day), the mapping between older Exchange item ids and Graph ids (30 days), under hashed keys.

What it never stores

Message bodies, subjects, addresses, attachments, contacts and calendar content. They pass through memory to answer the call. Logs carry no request URLs and no content; a test in the code base fails if an event ever carries a byte of content.

The Avakode EWS Bridge application asks for these Microsoft Graph application permissions, and nothing else: Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, Contacts.ReadWrite, User.Read.All, MailboxSettings.ReadWrite, Place.Read.All, GroupMember.Read.All. The administrator sign-in itself asks only for openid profile. The connection guide maps each permission to the EWS operations that need it.

Limiting the mailboxes

Application permissions reach every mailbox of the tenant unless you scope them. Exchange Online offers two ways: an Application Access Policy, and RBAC for Applications, Microsoft’s replacement. Both restrict the bridge to a mail-enabled security group; the guide has the PowerShell for each.

Where it runs

The hosted bridge runs on Cloudflare Workers, next to Microsoft Graph, and keeps its data in Cloudflare D1 and R2; daily database backups are deleted after 90 days. The self-hosted licence runs the same code as a Docker image on your server: then nothing but the daily licence check reaches us.

Who else handles data

Cloudflare (hosting), Microsoft (the calls your application sends, for your tenant only) and Paddle (payments). No analytics, no trackers, no third-party scripts on these pages except Paddle’s checkout. The full list is in the Privacy Policy.

Reporting a problem

Security issues go to support@avakode.com; we answer within two business days and faster for anything that affects customer data.