Skip to content

Questions to Ask an Email Vendor About Security and Data

Before you move company email to a new vendor, ask where the data lives, who processes it, and how you get it back out. A question list, with our own answers.

Koltrix Team4 min read
Server racks lit green in a dark room
Photo by Tyler on Unsplash
On this page(9 sections)
  1. Where the data lives
  2. Where are the servers, and who runs them?
  3. How is one customer's data separated from another's?
  4. Who else touches the data
  5. Who are your subprocessors?
  6. If there's AI, what does it see?
  7. Access and accounts
  8. Do you support two-factor authentication, and can it be required?
  9. How granular are permissions?
  10. Who at the vendor can read your mail?
  11. Certifications and audits
  12. Which third-party certifications do you hold?
  13. Resilience
  14. How is data backed up, and have you tested a restore?
  15. What happens during an outage?
  16. Getting out
  17. How do I export my data?
  18. What happens to my data when I cancel?
  19. Incidents
  20. How and when will you tell me about a breach?
  21. A copyable question list
  22. Key takeaways

Email holds contracts, invoices, password resets, customer complaints and every conversation your company has had with the outside world. Moving it to a new vendor means trusting them with all of that, so the security questions deserve more than a glance at a badge in the footer.

Below are the questions worth asking, why each one matters, and what a good answer sounds like. Where it's useful, we include Koltrix's own answers, including the ones that aren't flattering.

Where the data lives

Where are the servers, and who runs them?

You want a specific answer: a country or region, and whether the vendor runs its own infrastructure or builds on another provider. "The cloud" is not an answer.

This matters for data-residency requirements, for which laws apply to the data, and for understanding who else is in the chain.

Koltrix's answer: our servers run on OVHcloud in Frankfurt, Germany, in the European Union. We run the mail servers ourselves rather than building on another email provider's infrastructure. Cloudflare sits in front of the web application.

How is one customer's data separated from another's?

Multi-tenant systems are normal, but the separation model is worth understanding. Ask whether data is separated at the application level only, or also at the database level.

Koltrix's answer: each workspace has its own PostgreSQL schema, and attachments are kept in our own object storage.

Who else touches the data

Who are your subprocessors?

A subprocessor is any third party that processes your data on the vendor's behalf: hosting, payments, analytics, support tools and, increasingly, AI providers. Ask for the list, what each one receives, and how you'll be told when it changes.

If there's AI, what does it see?

This is the question many vendors answer vaguely. Ask specifically: which provider, what content is sent (headers only, or full bodies?), whether it's sent for every message or only when you use a feature, and whether it can be switched off.

Koltrix's answer: when AI is switched on for a workspace, sorting and spam scoring send headers, the subject and a truncated body to a classifier model (TypeSafe's Jev model, called through OpenRouter). Summaries and drafts use generative models, currently Google Gemini and DeepSeek models through OpenRouter. Our security page lists the details.

Access and accounts

Do you support two-factor authentication, and can it be required?

2FA should be standard. Ask whether admins can require it for everyone, and which methods are supported.

Koltrix's answer: 2FA is supported.

How granular are permissions?

Can you give someone access to support@ without giving them billing@? Can you remove access instantly when someone leaves? Shared mailboxes with per-mailbox permissions make offboarding much cleaner than shared passwords.

Who at the vendor can read your mail?

Ask under what circumstances staff can access customer content, how that access is controlled, and whether it's logged.

Certifications and audits

Which third-party certifications do you hold?

SOC 2 reports and ISO 27001 certificates are evidence that an independent auditor has reviewed a vendor's controls. If your customers send you security questionnaires, you may need vendors who hold them. Ask for the report or certificate itself, not just a logo.

Koltrix's answer: we don't hold SOC 2, ISO 27001 or any other third-party certification, and we haven't been audited. If your compliance team requires one, we're not the right vendor yet.

Resilience

How is data backed up, and have you tested a restore?

Ask how often backups run, where they're stored, how long they're kept and when a restore was last tested. A backup that has never been restored is a hope, not a plan.

Koltrix's answer: off-site backups are still being set up. Until we say they're running, don't treat Koltrix as your only copy of business-critical mail; you can export everything at any time.

What happens during an outage?

For incoming mail, ask what happens if the vendor's servers are unreachable. Sending servers generally queue and retry delivery for a period, but ask the vendor how they handle it and where status updates are published.

Getting out

How do I export my data?

The most important security question is often the exit. Ask what format exports come in, whether they include attachments and metadata, and whether you can export without contacting support.

What happens to my data when I cancel?

Ask how long data is kept after cancellation, whether you get warnings before deletion, and how deletion is confirmed.

Koltrix's answer: if a trial or subscription lapses, the workspace becomes read-only, so mail still arrives and everything stays readable and exportable. If it remains unpaid 30 days after that, the data is deleted, after three warning emails.

Incidents

How and when will you tell me about a breach?

Ask for the notification commitment in writing: how quickly, through which channel, and what information you'll get.

A copyable question list

Area Question
Location Where are servers located, and who operates them?
Isolation How is my data separated from other customers'?
Subprocessors Who processes my data, and how am I notified of changes?
AI Which AI providers see my mail, what do they see, and can I turn it off?
Access Is 2FA available and enforceable? How granular are permissions?
Staff access When can your staff read my content, and is it logged?
Certifications Which certifications do you hold? Can I see the report?
Backups How often, where, and when was the last restore test?
Export What format, does it include attachments, is it self-service?
Deletion What happens after cancellation, and how is deletion confirmed?
Incidents How quickly and how will you notify me of a breach?

Key takeaways

  • Ask for specifics: a region, named subprocessors, exact AI data flows, real export formats.
  • A vendor willing to say "we don't have that yet" is easier to trust than one with vague answers.
  • Certifications matter if your customers require them. Ask for the report, not the badge.
  • The exit path is a security question. Know how to get your data out before you put it in.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn
More in Guides →
  • Server racks lit green in a dark room
    Product

    Where Your Koltrix Data Lives

    Koltrix runs on its own servers on OVHcloud in Frankfurt. Where your mail, attachments and AI requests go, who else touches them, and what we don't have yet.

    5 min read