fluctuat

Security and subprocessing

Courtesy translation. The French version is authoritative: Sécurité et sous-traitance.

Last updated: July 2026

fluctuat sits in the mail path of your applications. This page describes, without embellishment, what we see, what we keep, and how the service is protected. The contractual detail is in the data processing agreement (DPA), downloadable as a PDF (French), which forms an integral part of the Terms of Service.

Permission model: Mail.Send, nothing else

The consent you grant to fluctuat's Microsoft application covers the Mail.Send permission only. We cannot read any mailbox, any calendar, any file in your tenant. Consent can be revoked at any time from your Microsoft 365 admin center, which immediately cuts off our ability to send.

fluctuat's Microsoft application is a Microsoft verified publisher: on the consent screen, Microsoft confirms the publisher's identity, Dizzus GmbH. You know exactly who you are granting this access to.

Message content: encrypted, transient, never logged

The body of a message is encrypted as soon as it is accepted, for the duration of its delivery only, and purged after handover to Microsoft 365 (at most 7 days in the event of persistent failure). The log you consult in the console contains only the headers (sender, recipients, subject, timestamp) and the delivery status, retained according to the duration of your plan (30 days to 12 months), then purged.

Isolation per customer

Each customer is a tenant isolated at the level of the database itself (forced row-level security): a query from one customer cannot reach another customer's data, even in the event of an application fault. Each customer has their own sending subdomain and their own credentials. This isolation between customers is absolute and not configurable: the Microsoft token is minted per tenant, so a customer can never send as a mailbox belonging to another customer.

Sender allowlist: optional

You decide whether to restrict the addresses your applications may send as. Declare an allowlist and fluctuat only sends as the listed addresses: a stolen credential can then only be used for those. Declare nothing and any address of your own Microsoft tenant may send, which stays bounded by Microsoft; you can tighten that perimeter on the Microsoft side with an Application Access Policy. In every case, the isolation between customers described above stays absolute.

Access and authentication

Everything travels over TLS: SMTP (STARTTLS or implicit TLS), console and API over HTTPS. Passwords and SMTP secrets are hashed with argon2id, never stored in clear text, and secrets are shown only once at creation. The console requires two-factor authentication (TOTP). Optionally, each SMTP credential can be restricted to the IP addresses or FQDNs of your servers: a stolen credential becomes unusable elsewhere.

Continuity and no message loss

An accepted message is written to a durable queue before acknowledgement, retried automatically in the event of an incident, and placed in a dead-letter queue with an alert rather than deleted: never any silent loss. The infrastructure is backed up daily to a remote site in France. In the event of non-payment, sending is suspended but nothing is destroyed.

Reversibility

You can leave at any time: revocation of consent on the Microsoft side, deletion of the account from the console, export of your account data in one click. Upon closure, the encryption key unique to your organization is destroyed: the encrypted content, including backup copies, becomes unreadable and is purged within 7 days (erasure by key destruction). Your other data is purged according to the timeframes of the DPA.

Sub-processors

What if you want no third party in the mail path

This is exactly what fluctuat Sovereign is for: the same application, run within your infrastructure, with your own Graph application. Your secret never leaves your walls and no message passes through Dizzus.

Documents

For a security question, a vulnerability report or an audit requirement: use the contact form, we respond quickly.