OAuth token storage
Feron encrypts the OAuth access and refresh tokens for your connected accounts, including Gmail, using AES-256-GCM before storing them in the database. Tokens are decrypted in memory when needed to access the connected service on your behalf. The OAuth state used to establish a connection is also encrypted.
Encryption in transit
Connections to Feron and its service providers use TLS/HTTPS. The Privacy Policy lists the providers that process data for Feron.
Access control
- Feron is invite-only; there is no public sign-up. Access requires an accepted invitation to a specific workspace.
- Each Gmail connection is scoped to the individual who created it and is not shared across a workspace.
- The application derives user and organization identity from verified authentication claims for every request.
Data isolation
Feron checks workspace membership on the server before granting access to data. Connections, saved conversations, and analytics belong to their customer workspace. Gmail access is further restricted to the person who created the connection.
Data minimization
- Feron requests only the Gmail scopes it needs (see the Gmail Connector page).
- Feron does not download attachments.
- Feron fetches relevant email when needed and does not retain a mailbox copy. Saved conversations and drafts may contain email content, as described in the retention policy.
- Search and listing use message metadata until you ask Feron to read a specific message in full.
Revocation and disconnection
Disconnecting a connection in Feron deletes its stored tokens and asks the provider to revoke the grant. You can independently revoke Feron in your Google Account permissions.
Logging and monitoring
Feron records operational and structured logs to run the service reliably and to investigate issues. Assistant tracing applies a sensitive-data filter to reduce sensitive content in captured traces. Logs and traces are retained on our providers' standard cycles.
Incident response
We investigate suspected security incidents, address their cause, and notify affected users where required by law.
Reporting a vulnerability
If you believe you have found a security vulnerability, please email security@feron.io. Include enough detail to reproduce the issue. Please do not publicly disclose it until we have had a reasonable opportunity to respond.
Certifications and assessments
Feron does not currently claim SOC 2 or ISO 27001 certification, a penetration-test attestation, or a completed cloud-application security assessment. Completed certifications and assessments will be listed here with their scope and date.
Contact
Security: security@feron.io. General support: support@feron.io.