Mailspan

Security posture

  • Customer-specific credentials and certificates stay scoped to the customer tenant.
  • Admin actions around pricing, credits, and credential changes should be audited.
  • Migration runs should be isolated by tenant and project.
  • Microsoft 365 setup must validate API permissions before scan or migration starts.
ControlExpectation
AuthenticationRole-separated customer and admin access
SecretsEncrypted at rest
BillingPrepaid credits only
AuditImmutable change trail