How Eskra keeps your emails secure
Our commitment to protecting your data
Updated December 2025
Security certifications and compliance
Eskra maintains the following security certifications:
- SOC 2 Compliant: Audited against strict security, availability, and confidentiality standards
- GDPR Ready: European data protection compliance for handling personal information
- Independently Audited: Third-party security assessments conducted regularly
- Google Verified: Passed Google's rigorous security review for Gmail and Sheets API access
- Microsoft Verified: Approved for Outlook integration after thorough security evaluation
How email loading works
When you log into Eskra, your emails are fetched in real-time directly from your email provider. We act as a secure bridge between you and your inbox:
- You authenticate with your email provider (Gmail, Outlook, etc.)
- Eskra requests only the emails you need to see right now
- Emails are displayed in your browser session
- When you log out, that session data is cleared
- Next time you log in, emails are fetched fresh again
Note: This means there's no database of your emails sitting on our servers. We simply pass data between your email provider and your browser while you're actively using Eskra.
Encryption implementation
Every piece of sensitive information is encrypted using modern cryptographic standards:
- Account passwords: Hashed with bcrypt and unique salts before storage
- OAuth tokens: Encrypted with AES-256 and rotated automatically
- Connected sheet data: Encrypted both in transit (TLS 1.3) and at rest (AES-256)
- IMAP/SMTP credentials: If you use custom email servers, credentials are encrypted before storage
- At rest: Database encryption with AES-256
🔒 Tip: Even our database administrators can't read your encrypted tokens or passwords - they're only decryptable by the application when needed.
OAuth security explained
OAuth 2.0 is the industry standard for secure third-party access. Here's why we use it:
- You never type your email password into Eskra
- You authenticate directly with Google or Microsoft
- We receive a limited-access token, not your password
- You can revoke access anytime without changing your password
Both Google and Microsoft require apps to pass extensive security reviews before granting OAuth verification. We completed these reviews and maintain compliance with their ongoing security requirements.
Tip: You can revoke Eskra's access anytime through your Google or Microsoft account settings.
Protecting your account with 2FA
Two-factor authentication adds a second verification step when logging in:
- Enable 2FA in Settings → Security
- Scan the QR code with an authenticator app
- Every login requires your password plus a 6-digit code
- Save backup codes in case you lose access to your authenticator
Note: Even if someone learns your password, they can't access your account without the time-based code from your authenticator app.
Complete data deletion
When you delete your Eskra account, we remove all associated data within 24 hours:
- Account credentials and profile information
- All OAuth tokens (access is automatically revoked)
- Connected email accounts and their settings
- Any custom-trained AI models
- Google Sheets connections and cached data
Warning: This deletion is permanent. We don't keep backups of deleted accounts, and your data can't be recovered.
Infrastructure and monitoring
Our infrastructure is designed with security as a priority:
- Hosted on enterprise-grade cloud infrastructure
- Automatic security patches applied within 24 hours of release
- 24/7 monitoring for suspicious activity and anomalies
- Regular penetration testing and vulnerability scanning
- Encrypted backups for system recovery (not containing email content)
Report a security concern
Found a potential security issue? Contact us immediately at [email protected]. We treat every report seriously and aim to respond within 24 hours.