# Email Archiving for SEC and FINRA Compliance

Archive Outlook, Gmail, and any IMAP mailbox in one WORM archive designed against SEC Rule 17a-4 and FINRA Rule 4511, alongside WhatsApp, Signal, and iMessage.

Source: https://commacompliance.com/email-compliance-archiving
Last updated: 2026-08-27

---

Email Archiving

# Your email is archived. That was never the hard part.

The exam covers every other channel too.

Comma captures Outlook, Gmail, and any IMAP mailbox into a WORM archive designed against SEC Rule 17a-4 and FINRA Rule 4511, then captures the 40+ channels your email archive was never going to see. One archive, one search, one export.

[Get in Touch](/get-in-touch)

Every archiving vendor covers email. It is the oldest, best-solved problem in compliance recordkeeping, and it is table stakes. If a vendor cannot capture Outlook and Gmail into an immutable archive, they’re not the choice for regulated firms.

The reason firms are still getting fined is that email stopped being the sole place business happens. Since 2021, over $3.2 billion in off-channel penalties across the SEC, FINRA, and the CFTC has landed almost entirely on conversations that never touched a mail server. Comma archives your email to the same standard everyone else claims, and then covers the channels that actually generate findings.

## What FINRA-compliant email archiving requires

[FINRA Rule 4511](/regulations/finra-rule-4511) requires firms to preserve books and records for the periods the applicable rules specify, in a format regulators can inspect. [FINRA Rule 3110](/regulations/finra-rule-3110) requires written supervisory procedures that match the channels your team actually uses, and evidence that review happened.

For email specifically, that means four things:

-   ### Capture is automatic, not voluntary

    Every inbound and outbound message, across every folder, written to the archive without an employee choosing to forward or copy anything.

-   ### Deletion by a user does not delete the record

    An employee clearing their inbox cannot shorten the retention period on a business record. That is the line between an archive and a backup.

-   ### The record is non-rewriteable

    Once written, a message cannot be altered or quietly replaced. Retention is measured from capture, and the clock is stated on the record.

-   ### Production is a workflow, not a project

    Search by custodian, date range, or thread, and export in a form an examiner accepts, without stitching systems together under deadline.

## SEC Rule 17a-4 and email retention

[SEC Rule 17a-4](/regulations/sec-17a-4) governs how broker-dealers preserve electronic communications, and it is the rule most email archiving copy points at. It requires records to be kept in a non-rewriteable, non-erasable format and produced on request in a reasonably usable electronic form.

Comma writes every captured email to [WORM storage](/resources/worm-storage) designed against Rule 17a-4 retention requirements, with retention measured from the moment of capture. Registered investment advisers face the parallel obligation under [Rule 204-2](/regulations/investment-advisers-act-rule-204-2), and dually registered firms are covered by the same archive rather than two.

### An Archive: not a backup

Deleted messages stay in the archive under your retention policy. An employee deleting a message from their inbox does not remove it from your compliance record, and that is what separates a real archive from a backup.

## Whichever mail system your firm runs

Comma connects to your existing mail provider. There is no migration, no change to how people send mail, and nothing to install on anyone’s machine.

1.  ### Microsoft 365 and Exchange Online

    Outlook email captured through a single tenant-wide admin consent. No per-user setup, no agent on anyone's machine, and the archive lives outside your Microsoft environment rather than inside the tenant it is meant to evidence.

    [See how Microsoft 365 capture works →](/channels/microsoft-365-compliance-archiving)

2.  ### Google Workspace and Gmail

    Gmail captured into an external archive that does not depend on Google Vault, alongside Drive, Chat, and Meet. Same admin-level connection, same immutable destination.

    [See how Google Workspace capture works →](/channels/google-workspace-compliance)

3.  ### Any IMAP mailbox

    [FastMail, Zoho Mail, ProtonMail via ProtonMail Bridge, and on-prem Microsoft Exchange](/channels/imap-email-compliance) with IMAP enabled. Enter credentials once in the dashboard and capture runs from that point forward, including full headers, plain-text and HTML bodies, attachments, and folder structure.

    [See the setup guide →](https://docs.commacompliance.com/getting-started/imap-email-setup/)

4.  ### Email lands where every other channel lands

    Captured mail is written to the same archive as WhatsApp, Signal, iMessage, and 40+ other channels. One search interface, one supervision queue, one export. Firms carrying more than one mail system after an acquisition get the same result without keeping two archives running.

    [See the full list of 40+ channels →](/platform-integrations)

*Image: Unified archive showing Gmail, WhatsApp, and iMessage messages in one searchable inbox*

Gmail, WhatsApp, and iMessage: one archive, one search, one export

✕

*Image: Unified archive showing Gmail, WhatsApp, and iMessage messages in one searchable inbox*

## The channels your email archive was never going to see

The moment an employee texts a client from a personal phone, that conversation never touches your mail server, and no record of it exists unless something else captures it. Legacy archivers struggle with those channels for a specific reason. Three things trip them up:

-   ### There is no compliance API to call

    WhatsApp, iMessage, and Signal don't expose a feed for archivers to pull from. Tools built around APIs simply can't see these channels, so they either skip them or ask your people to change apps.

-   ### Sync-based capture leaves gaps

    Archivers that copy from a backup or a periodic sync miss anything sent between cycles, and anything edited or deleted before the next pull. A gap in the record is a finding in an exam.

-   ### The message lives on the device

    Business conversations on personal phones never touch a server your archiver can reach. If capture doesn't happen on the channel itself, the record never exists.

## Two archives means two exam exports

Filling those gaps with a second archive means another vendor, another integration, another search interface, and another supervisory workflow your team has to run in parallel. Cross-channel search becomes manual reconciliation, done under deadline pressure while an examiner is waiting.

When an examiner shows up, they do not care which platform stored what. They want every message between Rep X and Client Y, across every channel, immutable, and quickly produceable. Comma captures email and non-email channels into the same archive, so that request is one search and one export.

## Your email archive is only half the record.

A 20-minute walkthrough: capture across 40+ channels, real-time flagging, exam-ready exports.

[Get in Touch](/get-in-touch)[Pricing](/pricing)

## Frequently asked questions

Which email providers does Comma cover?

Microsoft 365 and Exchange Online, Google Workspace and Gmail, and any mailbox that speaks IMAP, including FastMail, Zoho Mail, ProtonMail via ProtonMail Bridge, and on-prem Microsoft Exchange with IMAP enabled. If your provider exposes an IMAP endpoint, Comma can connect to it.

Is Comma an email archiving product or a messaging product?

Both, in one archive. Email is captured to the same standard and stored in the same WORM archive as WhatsApp, Signal, iMessage, and 40+ other channels. Firms usually come to us for the channels their current archiver misses, then consolidate email in rather than run two systems.

Do we have to replace our existing email archive?

No. Some firms keep an incumbent email archive in place and use Comma for the channels it cannot reach. Others consolidate everything into Comma so exam production is a single export. Both work, and the second one is cheaper to run and faster under a deadline.

Our firm also has a broker-dealer. Do we need two separate archives?

No. If your firm is dually registered, Comma covers both your Rule 204-2 obligations as an RIA and your Rule 17a-4 obligations as a broker-dealer from a single platform. The same capture infrastructure, the same retention policy, the same production workflow.

What gets captured from a mailbox?

Full message headers, body in both plain text and HTML parts, and attachments. Comma preserves folder structure, including INBOX, Sent, Drafts, and custom folders, and keeps deleted messages in the archive under your retention policy.

How quickly do emails appear in the archive?

For IMAP mailboxes Comma polls every five minutes by default, and servers that support IMAP IDLE deliver new messages to the archive within seconds. Microsoft 365 and Google Workspace capture is push-based rather than polled.

Where do our mailbox credentials go?

Credentials are encrypted at rest using AES-256 and never stored in plaintext. We recommend an app-specific password rather than an account password, since it can be revoked independently without changing a login. For on-prem Exchange and providers that support OAuth, Comma connects via OAuth instead of stored credentials. If you disconnect the integration, the credentials are wiped immediately.

Does anything need to be installed on user devices?

No. Comma connects to the mail server directly. There is no client agent, no email client plugin, and no change to how users send or receive email.
