Security
Identity and least privilege
CalendarGuardian uses provider-native OAuth authorization and does not receive Microsoft or Google passwords. The Microsoft connector requests basic identity and delegated calendar read/write access. The Google connector requests basic identity, Calendar event access, and Calendar-list discovery needed to protect writable calendars.
Credential and transport protection
Server-side OAuth token material and retained review snapshots are encrypted using AES-256-GCM at the application layer. Production secrets and encryption keys are maintained outside source code in protected hosting configuration. Production application, callback, and webhook traffic uses HTTPS.
Provider notification validation
Microsoft Graph subscriptions use protected client-state values. Google notification channels use per-channel tokens and identifiers. Pausing the master calendar filter removes provider subscriptions and stops automatic renewal, notification processing, catch-up scans, and automatic actions.
Threat intelligence and privacy
Enabled threat-feed files are downloaded to CalendarGuardian and cached for local matching. Calendar invitation content, organizer addresses, and event details are not sent to feed providers for lookup. Feed status, source, entry count, freshness, errors, and licensing notes are exposed in the product. The initial enabled source is the CERT.PL Warning List. URLhaus and ThreatFox adapters remain disabled unless required credentials and commercial-use confirmation are configured.
User control and deletion
Users can pause filtering, disable threat intelligence for their account, disconnect and withdraw consent, or permanently delete the CalendarGuardian account and service data. Google disconnection invokes Google's OAuth revocation endpoint. Microsoft disconnection deletes CalendarGuardian's stored token and may be supplemented with provider-side removal through Microsoft app-permission settings.
Limitations
CalendarGuardian can produce false positives and false negatives. It does not claim SOC 2, ISO 27001, FedRAMP, HIPAA certification, or another independent security certification unless DealDoctor expressly publishes that the certification has been obtained and identifies its scope.
Responsible disclosure
Send suspected vulnerabilities to support@dealdoctor.pro with the subject SECURITY - CalendarGuardian. Do not include passwords, tokens, secrets, or data you are not authorized to access.