STAR Registry Listing for
Aveldra — Microsoft 365 security cockpit for MSPs
Aveldra — Microsoft 365 security cockpit for MSPs
What it does: Detects and risk-scores third-party OAuth apps, monitors sign-in and audit logs for suspicious activity, flags new mailbox forwarding rules, and provides guided remediation with preview, confirmation, audit logging, and undo — across multiple managed customer tenants.
Deployment model: Multi-tenant SaaS (public cloud, EU region).
Data handling: Security metadata only (app names/IDs, permissions, sign-in metadata, forwarding-rule metadata). No email or file content is ever read or stored. OAuth tokens are stored encrypted (AES); transport is TLS only.
Hosting & sub-processors: Application and database on Fly.io (Frankfurt, EU); frontend on Vercel; encrypted off-site backups on Backblaze (EU). Public sub-processor list and DPA available.
Compliance posture: GDPR-aligned; CSA STAR Level 1 self-assessment (CAIQ v4.1). Trust Center: https://www.aveldra.de/sicherheit · security.txt (RFC 9116): https://www.aveldra.de/.well-known/security.txt

Listed Since: 08/01/2026
STAR Level 1

CAIQ Self-assessment v4.1.0
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed 7 days ago, on August 01, 2026.