security

Security Statement

Physical security

EnovaPoint JungleMail cloud products are available in a choice of five Microsoft Azure data centers in a different regions. Azure infrastructure meets a broad set of international compliance standards, including ISO 27001, SOC 1, and SOC 2, HIPAA, and country specific standards including Australia IRAP, UK G-Cloud.  You can choose to store and process your data in U.S.A. (US East), EU (Netherlands), Australia (Australia South East), U.K. (UK South) and Canada (Canada Central). All these JungleMail cloud instances are standalone, that means all file storage, databases, and backups are separated. 

Even though your data is not stored on our premises, we employ high security standards safeguarding our office premises or remote access. That includes monitored on-premises access, no wifi, VPN. 

Data Encryption and retention

All your data, including backups is encrypted at rest and traffic is encrypted in transit with TLS 1.2 or higher. 
The backups are encrypted and use geo-redundant and zone-redundant storage depending on Data center location to ensure compliance with data residency requirements.

Your data privacy

 All information uploaded to our servers remain yours.  We’ll never share, copy or modify your data. Only certain members of our team have authorization to access the servers with customers data. For more information, please review our Privacy Policy.

Application security

We perform regular automated vulnerability scanning, regulatory compliance checks using Azure Security Center tools. Manual penetration tests by third-party take place annually and all reported issues are addressed.

Download the full list of EnovaPoint’s Security Controls

Quality and Information Security

We strive to build long-term value, based on customer feedback while maintaining integrity and Information Security. Find out more on our Quality and Information Security policy page.

GDPR Compliance

As an EU-based company, EnovaPoint ensures JungleMail 365 fully complies with the General Data Protection Regulation (GDPR) and other applicable data privacy laws. Our Data Processing Addendum outlines transparent practices: we process data only as instructed, implement strict security measures, and assist with employee data requests.

We maintain GDPR-aligned safeguards including encryption at rest and in transit, pseudonymization, disaster recovery protocols, and regular system testing to ensure confidentiality, integrity, and availability.

For GDPR-related inquiries, our support team is ready to assist. Your data remains yours—always. Read more about our GDPR Compliance.

Certificates and Reports

ISO 9001:2015 Quality Management System

See certificate

ISO/IEC 27001:2022 Information Security Management System

See certificate

Accessibility standard

Accessibility

Learn more

GDPR logo

GDPR

Learn more

EnovaPoint management requires employees and third-party contractors with access to Customer Data to commit to written information security, confidentiality, and privacy responsibilities. These responsibilities specifically encompass the respectful and lawful handling of all customer data, with firm obligations to avoid unauthorized disclosure, misuse, alteration, or destruction of this information, and shall survive termination or change of employment or engagement. 

As part of our comprehensive hiring process, we conduct background checks on all job applicants in compliance with applicable laws, regulations, and ethics. These checks are designed to validate the applicant’s history and assess their suitability for handling sensitive information. Our aim is to ensure that all our employees have a demonstrable track record of integrity, with no known incidents related to information leakage, unauthorized disclosure of proprietary information, or similar breaches of trust.

All employees must participate in regular information security training. This training program is designed to ensure they remain informed about our organization’s policies, procedures, and any changes thereto that are related to their work.

EnovaPoint ensures that all agreements with third-party vendors involved in sub-processing Customer Data incorporate stringent information security, confidentiality, and data protection 7 requirements. These agreements are regularly reviewed and assessed, at least every 12 months, to verify that the information security and data protection provisions remain relevant and effective.

EnovaPoint is committed to embedding privacy considerations into every stage of our product development and business operations, following the principle of ‘Privacy by Design’. This approach involves proactively integrating data protection measures into our system architectures, business processes, and practices from the onset, rather than as an afterthought. We adopt a ‘data minimization’ approach where we only collect, process, and store the minimal amount of personal data necessary for legitimate business purposes, in line with GDPR principles.

EnovaPoint adheres to the principle of least privilege, ensuring that users only have access to the information and resources necessary to perform their job functions. This access is determined by Senior Management and reviewed quarterly to ensure alignment with current job duties. Any access found to be inappropriate or unnecessary is immediately revoked.

Password Management Policy governs the creation, use, and modification of passwords used to access EnovaPoint’s and third-party vendor operating systems, applications, and data. The Company enforces a strong password policy, which includes requirements for password length, complexity, and expiration, to protect the privacy and security of data, whether at rest or in transit.

EnovaPoint implements formal, documented change control procedures for managing modifications to information systems, supporting infrastructure, and facilities. Significant changes that impact Customer Data or supporting systems are communicated to customers prior to implementation via in-app alerts or by email. Stakeholder approval is obtained prior to the implementation of changes.

We employ a range of encryption methods to protect any Customer Data stored at rest, adapted to suit the storage medium. These include:

• Microsoft SQL Server on Azure: Transparent Data Encryption (TDE) using the AES256 algorithm.

• Azure Virtual Machines: We secure data with Azure Disk Encryption, also using the AES-256 algorithm.

• Azure Storage: Data is protected by Azure Storage encryption, utilizing the AES-256 algorithm.

• Microsoft 365: EnovaPoint’s internal documents, including customer quotations, invoices, and agreements, are secured both at rest (using BitLocker and DKM) and in transit (using TLS) with end-to-end encryption.

• Workstations: We use BitLocker for encrypting data on workstations.

We ensure that all confidential data, including Customer Data, transmitted across public networks, or to external entities, is securely protected and encrypted during transfer to maintain the integrity and privacy of the information. We implement robust security protocols such as HTTPS, TLS 1.2 or higher, SSL, and StartTLS for SMTP traffic to secure data in transit.

EnovaPoint implements and maintains industry-standard best practices to protect our corporate network, including but not limited to, the use of network firewalls, intrusion detection or prevention systems, and anti-virus/anti-malware software on all supported systems. The performance of anti-virus/anti-malware software is monitored on a regular basis. This monitoring ensures that scheduled scans are completed properly and that threat definitions are updated daily or as they become available from the vendor. Any identified issues are immediately investigated and remediated.

EnovaPoint conducts annual penetration testing on applications that store or provide access to Customer Data, including personal data. This process is also repeated whenever significant changes are made to these applications. The latest penetration test report is made available to customers upon request.

EnovaPoint has established policies and procedures to effectively respond to suspected or actual security or privacy incidents that result in breach of confidential data. These procedures include maintaining an Incident Register, which records the incident description, severity level, business risk type, investigation results, and measures to prevent similar incidents in the future.

EnovaPoint is committed to conducting regular business continuity risk assessments to identify relevant risks, threats, impacts, likelihood, and necessary controls and procedures. Based on these assessment results, EnovaPoint will document, implement, and review BC/DR plans annually. These plans aim to ensure the swift restoration of availability and access to Customer Data in the event of a physical or technical incident that results in the loss or corruption of such data.

EnovaPoint has a well-documented backup and retention procedure, which ensures that backup copies of data are created, stored, and retired at defined intervals. These backups are tested regularly to ensure the integrity and availability of the data.