VANTAGE AEGIS MAIL · 1.2.4

Sign in on the provider’s real website.

Gmail and Outlook/Microsoft 365 use modern read-only provider APIs. Yahoo, iCloud, Fastmail, and other providers use strict-TLS IMAP with an app-specific password when provider-native website authorization is unavailable.

G

Gmail + Google Workspace

OAuth 2.0 with PKCE opens Google in the system browser. Vantage requests gmail.readonly and retrieves selected recent inbox messages through the Gmail API.

It cannot send, delete, modify, label, or archive Gmail messages with this permission.

M

Outlook + Microsoft 365

OAuth 2.0 with PKCE opens Microsoft in the system browser. Vantage uses delegated Mail.Read through Microsoft Graph for personal, work, and school accounts supported by the publisher app registration.

No Microsoft client secret is stored in the desktop application. The publisher registers http://localhost/oauth/callback as the mobile/desktop redirect; Vantage chooses a temporary local port at sign-in.

A

Yahoo, iCloud, Fastmail + IMAP

The Advanced sign-in path uses certificate-validated TLS 1.2 or newer and an app-specific password. Do not use your normal provider password when the provider requires an app password.

Custom IMAP hosts are validated and connections are limited to secure TLS.

DATA BOUNDARY

Tokens stay on your device.

Provider access and refresh tokens are encrypted using operating-system protected storage when available. Gmail API and Microsoft Graph requests travel directly between Vantage and the provider. Aegis account credentials are excluded from projects, Continuity packages, Marketplace requests, AI prompts, and ordinary cloud-workspace files.

What Vantage stores

Encrypted provider authorization, account identity, sync timestamps, and locally cached message content.

What Vantage blocks

Remote images by default, active message scripts, automatic attachment opening, unexpected API hosts, redirects, oversized provider responses, and untrusted links.

Remove access

Remove the account in Vantage Aegis Mail to delete the stored authorization. Google revocation is attempted automatically. Microsoft, Apple, Yahoo, and other provider access can also be revoked from the provider account security page.

Delete local mail

Removing an account does not automatically delete messages already imported into the local organizer. Delete those messages or the Vantage application-data folder separately when needed.

A
Provider setup belongs to That1Dev, not customers.The public release must contain approved Google and Microsoft public client IDs. End users only select a provider, enter the mailbox address, and approve the provider consent screen.

Read the Privacy Policy Contact privacy support