Questions to Ask an Email Vendor About Security and Data
Before you move company email to a new vendor, ask where the data lives, who processes it, and how you get it back out. A question list, with our own answers.

On this page(9 sections)
- Where the data lives
- Where are the servers, and who runs them?
- How is one customer's data separated from another's?
- Who else touches the data
- Who are your subprocessors?
- If there's AI, what does it see?
- Access and accounts
- Do you support two-factor authentication, and can it be required?
- How granular are permissions?
- Who at the vendor can read your mail?
- Certifications and audits
- Which third-party certifications do you hold?
- Resilience
- How is data backed up, and have you tested a restore?
- What happens during an outage?
- Getting out
- How do I export my data?
- What happens to my data when I cancel?
- Incidents
- How and when will you tell me about a breach?
- A copyable question list
- Key takeaways
Email holds contracts, invoices, password resets, customer complaints and every conversation your company has had with the outside world. Moving it to a new vendor means trusting them with all of that, so the security questions deserve more than a glance at a badge in the footer.
Below are the questions worth asking, why each one matters, and what a good answer sounds like. Where it's useful, we include Koltrix's own answers, including the ones that aren't flattering.
Where the data lives
Where are the servers, and who runs them?
You want a specific answer: a country or region, and whether the vendor runs its own infrastructure or builds on another provider. "The cloud" is not an answer.
This matters for data-residency requirements, for which laws apply to the data, and for understanding who else is in the chain.
Koltrix's answer: our servers run on OVHcloud in Frankfurt, Germany, in the European Union. We run the mail servers ourselves rather than building on another email provider's infrastructure. Cloudflare sits in front of the web application.
How is one customer's data separated from another's?
Multi-tenant systems are normal, but the separation model is worth understanding. Ask whether data is separated at the application level only, or also at the database level.
Koltrix's answer: each workspace has its own PostgreSQL schema, and attachments are kept in our own object storage.
Who else touches the data
Who are your subprocessors?
A subprocessor is any third party that processes your data on the vendor's behalf: hosting, payments, analytics, support tools and, increasingly, AI providers. Ask for the list, what each one receives, and how you'll be told when it changes.
If there's AI, what does it see?
This is the question many vendors answer vaguely. Ask specifically: which provider, what content is sent (headers only, or full bodies?), whether it's sent for every message or only when you use a feature, and whether it can be switched off.
Koltrix's answer: when AI is switched on for a workspace, sorting and spam scoring send headers, the subject and a truncated body to a classifier model (TypeSafe's Jev model, called through OpenRouter). Summaries and drafts use generative models, currently Google Gemini and DeepSeek models through OpenRouter. Our security page lists the details.
Access and accounts
Do you support two-factor authentication, and can it be required?
2FA should be standard. Ask whether admins can require it for everyone, and which methods are supported.
Koltrix's answer: 2FA is supported.
How granular are permissions?
Can you give someone access to support@ without giving them billing@? Can you remove access instantly when someone leaves? Shared mailboxes with per-mailbox permissions make offboarding much cleaner than shared passwords.
Who at the vendor can read your mail?
Ask under what circumstances staff can access customer content, how that access is controlled, and whether it's logged.
Certifications and audits
Which third-party certifications do you hold?
SOC 2 reports and ISO 27001 certificates are evidence that an independent auditor has reviewed a vendor's controls. If your customers send you security questionnaires, you may need vendors who hold them. Ask for the report or certificate itself, not just a logo.
Koltrix's answer: we don't hold SOC 2, ISO 27001 or any other third-party certification, and we haven't been audited. If your compliance team requires one, we're not the right vendor yet.
Resilience
How is data backed up, and have you tested a restore?
Ask how often backups run, where they're stored, how long they're kept and when a restore was last tested. A backup that has never been restored is a hope, not a plan.
Koltrix's answer: off-site backups are still being set up. Until we say they're running, don't treat Koltrix as your only copy of business-critical mail; you can export everything at any time.
What happens during an outage?
For incoming mail, ask what happens if the vendor's servers are unreachable. Sending servers generally queue and retry delivery for a period, but ask the vendor how they handle it and where status updates are published.
Getting out
How do I export my data?
The most important security question is often the exit. Ask what format exports come in, whether they include attachments and metadata, and whether you can export without contacting support.
What happens to my data when I cancel?
Ask how long data is kept after cancellation, whether you get warnings before deletion, and how deletion is confirmed.
Koltrix's answer: if a trial or subscription lapses, the workspace becomes read-only, so mail still arrives and everything stays readable and exportable. If it remains unpaid 30 days after that, the data is deleted, after three warning emails.
Incidents
How and when will you tell me about a breach?
Ask for the notification commitment in writing: how quickly, through which channel, and what information you'll get.
A copyable question list
| Area | Question |
|---|---|
| Location | Where are servers located, and who operates them? |
| Isolation | How is my data separated from other customers'? |
| Subprocessors | Who processes my data, and how am I notified of changes? |
| AI | Which AI providers see my mail, what do they see, and can I turn it off? |
| Access | Is 2FA available and enforceable? How granular are permissions? |
| Staff access | When can your staff read my content, and is it logged? |
| Certifications | Which certifications do you hold? Can I see the report? |
| Backups | How often, where, and when was the last restore test? |
| Export | What format, does it include attachments, is it self-service? |
| Deletion | What happens after cancellation, and how is deletion confirmed? |
| Incidents | How quickly and how will you notify me of a breach? |
Key takeaways
- Ask for specifics: a region, named subprocessors, exact AI data flows, real export formats.
- A vendor willing to say "we don't have that yet" is easier to trust than one with vague answers.
- Certifications matter if your customers require them. Ask for the report, not the badge.
- The exit path is a security question. Know how to get your data out before you put it in.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

