Home/Products/Mail Journaling
Email journaling & compliance archive

Every message captured.
Cloud and on-premise.

One platform journals every email across Office 365 and on-premise Exchange, preserves the original message as tamper-evident evidence, and produces it on demand for legal, audit, or a regulator — with a chain of custody that holds up.

Office 365 + on-premiseOriginal .eml evidenceAppend-only auditPurpose-bound access
app.creodata.mjs · Email viewerActivity #A-2291
Q2 board pack — final approval
From t•••••@creodata · To 4 recipients · 2026-06-18 14:21 UTC
Office 365
ImmutableLegal holdRetain 7y
Original evidence · EMLSaved
SHA-256a91f3c…7b8a52e4d1
Objecteml/2026/06/…0142.eml
Reconciled2026-06-18 14:23 UTC
Download original .emlView audit
Download routes through an audited endpoint — never a direct storage URL.
2
Mail sources
Office 365 and on-premise Exchange, captured by one platform
5,000+
Mailboxes at go-live
Proven scale, with a 10,000-mailbox roadmap
1M / day
Peak journaled emails
Transport-level capture with durable export
100%
Hash-verified evidence
Every original .eml is SHA-256 hashed and reconciled
The problem

Having the email is not the same as being able to produce it.

Most institutions keep every message. Far fewer can hand a regulator eighteen months of one executive's mail and prove that not one of them has been altered.

An archive that cannot show chain of custody is storage. Evidence is what holds up when someone challenges it.

  • You have the messages but cannot prove they are unaltered

    Journaled mail sits in a mailbox or a file share with no fingerprint, no reconciliation and no record of who has touched it since.

  • Cloud and on-premise are archived two different ways

    Office 365 and on-premise Exchange mailboxes land in different systems with different search, so one request gets two answers.

  • Anyone with admin rights can read anything

    Privileged staff can open mailboxes without a stated purpose, and nothing records that they did.

What changes

What changes when email becomes evidence.

Produce any message, provably unaltered

One original .eml per message, SHA-256 hashed, reconciled by a worker, and downloadable only through an audited endpoint.

One archive across Office 365 and on-premise Exchange

Both sources are captured at the transport layer into the same evidenced, searchable archive.

Nobody browses the archive without a reason on record

Every search, view and export is bound to a compliance activity with expiry, and four-eyes sign-off protects the sensitive actions.

Legal hold that holds

Place and lift holds by mailbox or class with the full chain-of-custody record preserved.

The admin console

Activate, hold, and produce — every action audited.

Compliance officers and administrators work in one console. Office 365 and on-premise mailboxes have dedicated pages, sensitive data sits behind a compliance activity, and every view writes to a tamper-evident trail. Click through the surfaces a team uses every day.

app.creodata.mjs/office365/users
Journaling/Office 365 users
Activity #A-2291 · 38m left
Office 365 users
Mailboxes synced from Entra ID · journaling via Microsoft Graph subscriptions
Bulk activate
O365 mailboxes
3,420
Journaling active
3,118
Pending
296
Needs review
6
MailboxSourceJournalingLast syncedAction
AN
Amani Njoroge
a.njoroge@creodata
Office 365Active2m agoView
FA
Fatima Al-Mansouri
f.almansouri@creodata
Office 365Active2m agoView
JS
João da Silva
j.silva@creodata
Office 365Pending11m agoActivate
CX
Chen Xiaoming
c.xiaoming@creodata
Office 365Active2m agoView
AR
Alex Rivera
a.rivera@creodata
Office 365Pending11m agoActivate
LK
Leila Karimi
l.karimi@creodata
Office 365Active2m agoView

Twelve capabilities, one compliance archive.

From capture to production — each step is evidenced and audited.
Complete journaling

Every inbound, outbound, and internal message captured at the transport layer across both sources — nothing slips through.

Original .eml evidence

One immutable original per message in object storage, SHA-256 hashed, with a reconciliation worker proving it landed — so what you produce is provably the message that was sent.

Append-only audit

A hash-chained, tamper-evident trail of every access and action, fanned out to your SIEM through a transactional outbox — so anyone who looked at a message is on the record, and the record cannot be edited.

Purpose-bound access

No mailbox, email, search, or export returns data without an active compliance activity scoped to the target, with expiry — so nobody browses the archive out of curiosity, and every access has a reason attached.

Maker-checker approvals

Four-eyes sign-off on the sensitive actions — body search, attachment download, PDF and eDiscovery export, hold release — so no single administrator can read, export or release a hold alone.

PII masking

Mailbox names, UPNs, and recipients masked by default; reveal is permission-gated and itself written to the audit trail — so investigators see only what their activity requires.

eDiscovery & search

Search the full archive by sender, recipient, date, subject, or content across both sources, and produce results in seconds.

Retention & legal hold

Configure retention by mailbox or class, place and lift legal holds, with the full chain-of-custody record preserved — so retention is a policy the platform enforces, not a task someone remembers.

Bulk activation

Activate thousands of mailboxes from a CSV through a durable saga — per-row status, retry of failed rows, approval gate — so a bank-wide rollout is one approved job, with every failed mailbox visible and retried, not lost.

Source-aware activation

Office 365 and on-premise route through one activation service — no cloud subscription is ever created for an on-prem mailbox — so a hybrid estate is onboarded from one console without misrouted mailboxes.

Subscription health

Per-mailbox EWS subscription state in the database, worker leases, and stale detection — so you know every journaled mailbox is actually being captured right now, not just that the service is up.

Role-based access

Least-privilege roles and separation of duties — service accounts hold only the scopes they need, enforced down to the bucket — so the reach of any one account stays small.

Chain of custody

The original message — provably preserved, not just stored.

Every journaled email keeps exactly one original .eml in object storage, fingerprinted with SHA-256. A reconciliation worker proves it landed — a "pending" pointer is never mistaken for evidence. Download only ever happens through an audited endpoint.

Exactly one EML_ORIGINAL per message, with status moving pending → uploading → saved — never a dangling pointer.
A reconciliation worker detects missing, stale, or hash-mismatched evidence and requeues the export automatically.
EML download is served only through an audited endpoint — the UI never receives a direct storage URL.
The audit log is append-only and hash-chained; a scheduled job re-verifies the chain and alerts on any break.
Evidence lifecycle
Captured
Message journaled at the transport layer from O365 or EWS.
Hashed
Original .eml written once and SHA-256 fingerprinted.
Reconciled
Worker proves the object exists and matches its hash.
audit_log · hash chain v3append-only
#5512EmlDownloaded · A-2291a91f3c
#5511EmailViewed · A-22917b8a52
#5510ActivityStarted · A-2291c20b7e
Two sources, one archive

Office 365 and on-premise Exchange — captured the same way.

Cloud mailboxes are journaled through Microsoft Graph subscriptions; on-premise mailboxes through EWS streaming workers with LDAP user sync. Both land in the same evidenced, audited archive — deployed on Azure or your own Kubernetes.

Office 365
Microsoft Graph subscriptions
Microsoft Graph change subscriptions per mailbox, renewed on a durable schedule.
Users synced from Entra ID; subscriptions checked before create, so re-runs never duplicate.
Idempotent activation keyed per request — repeat calls return the same result.
Runs as Azure Function Apps with Entra ID identity.
On-premise Exchange
EWS streaming + LDAP sync
EWS streaming workers subscribe only to mailboxes flagged for journaling in the database.
Users synced from LDAP with a read-only bind account; errors captured by stage.
Per-mailbox subscription state and worker leases live in Postgres — they survive restarts.
A crashed worker’s lease expires in seconds and another replica reclaims the shard.
One platform, deployed your way

A storage-provider abstraction and durable orchestration mean every feature works identically in the cloud and on your own infrastructure.

AzureOn-prem Kubernetes
Azure Functions
Stateless capture, query, export, and notification apps.
PostgreSQL 16
Org users, evidence, audit log, and subscription state.
MinIO / Blob
Storage-provider abstraction for original .eml objects.
RabbitMQ + Saga
Durable bulk jobs and the transactional outbox relay.

Make your email defensible — across every mailbox.

See Mail Journaling capture, hold, and produce a live mailbox — cloud or on-premise — with full chain of custody.