Security

How Turret protects your firm's data.

Access model

Turret connects to Google Workspace via Domain-Wide Delegation using a service account your Google Workspace Super Admin authorizes. The service account has read-only scopes: gmail.readonly and admin.directory.user.readonly. Turret cannot send, modify, delete, or forward any email. Authorization can be revoked at any time from your Google Admin Console without contacting Turret.

Encryption

Credentials (service account keys) are encrypted at rest using AES-256-GCM before being written to the database. Keys are stored separately from data and rotated on a defined schedule. All traffic is encrypted in transit via TLS 1.2+.

Tenant isolation

Every database record is scoped to a tenant ID. Application-layer queries always filter by tenantId. One firm's data is never accessible to another firm, even on the same infrastructure.

PII handling

Pattern-matched snippets are redacted before being written to the database. Social security numbers and credit card numbers detected in email content are replaced with masked values before storage. Raw email content is compressed and stored for archive purposes but is never logged or exposed in error messages.

Staff access

Turret staff can access operational metadata (job status, error logs, scan counts) for support purposes. Turret staff do not access email content as part of normal operations. All access is logged.

Compliance posture

  • SOC 2 Type 1 in progress
  • CASA Tier 2 security review planned prior to marketplace listing
  • Data processing addendum available upon request

Security questions? Contact nick@musecap.com.

← Back to home