Email Communications | Connector for Email
What Is the Shield Connector for Email?
Email remains the single highest-volume regulated communication channel at most financial institutions. Despite the proliferation of instant messaging platforms, collaboration tools, and mobile applications, email continues to be the primary channel for client instructions, trade confirmations, advisory communications, formal business correspondence, and the written record of decisions across regulated financial services firms globally. For compliance purposes, email is the foundational layer of the eComms compliance programme — the channel that has been subject to regulatory recordkeeping obligations the longest, the channel most frequently scrutinised in regulatory examinations, and the channel whose absence from the compliance archive is never acceptable.
Shield’s Email connector provides platform-agnostic, comprehensive email capture across the full range of enterprise email infrastructure deployed by regulated financial institutions — including Microsoft Exchange, Microsoft 365 and Office 365, Gmail and Google Workspace, and other corporate email platforms — ingesting messages, attachments, and the full metadata layer directly into Shield’s compliance platform. From the moment email data enters Shield, it is available for AI-powered surveillance, investigation, regulatory archiving, and eDiscovery alongside every other channel the firm uses.
Email data does not exist in isolation. The same employees communicating over email are also using Bloomberg IB, Microsoft Teams, Symphony, voice, and mobile — often about the same trades, clients, and decisions. Shield ensures that email is reviewed in context alongside every other regulated channel, enabling compliance teams to reconstruct the complete picture of any business interaction rather than reviewing channels in isolation.
Why Email Compliance Is Complex
Email is not a straightforward channel to capture and surveil at the fidelity required for financial services compliance. Several specific challenges arise consistently across regulated firms:
- Volume and noise. Financial institutions generate millions of emails per day across their workforce. The vast majority are operationally routine, but a small fraction carries genuine compliance risk. Without intelligent filtering and AI-assisted prioritisation, compliance teams are overwhelmed by volume and unable to focus review resources on the communications that matter. Email surveillance without AI prioritisation produces high alert volumes, compliance fatigue, and missed genuine risk signals.
- Thread reconstruction and context. Email compliance is not simply about capturing individual messages. Regulatory requirements — particularly trade reconstruction under MiFID II and Dodd-Frank — require that the full thread of a conversation be reconstructable, including forwarded chains, inline replies, embedded attachments, and calendar-linked communications. Many archiving solutions capture messages in isolation, breaking the thread context that makes surveillance meaningful and that is required for complete trade reconstruction.
- Platform heterogeneity and hybrid environments. Most large financial institutions operate a combination of on-premises Exchange servers and cloud-based Microsoft 365 tenants, Gmail, and potentially other email platforms — often across multiple geographies and legal entities. Capturing email consistently and completely across heterogeneous infrastructure — without gaps, duplications, or jurisdictional blind spots — requires a connector capable of handling the full complexity of enterprise email environments.
- Attachment handling and embedded content. Business-critical content frequently lives in email attachments — spreadsheets, PDFs, presentations, and documents that accompany or supplement the email body text. Effective email compliance requires that attachments are ingested, indexed, and made searchable alongside the messages they accompany, not stored as opaque binary files that are inaccessible for surveillance and eDiscovery.
- Cross-channel continuity. Email rarely represents the complete picture of a business interaction. A trade may be negotiated over Bloomberg IB, confirmed via email, and followed up on Teams or mobile. Compliance architectures that treat email as a standalone archive — separate from other channels — make cross-channel reconstruction slow, error-prone, and structurally incomplete for the regulatory and litigation contexts where it matters most.
Key Features of the Shield Email Connector
Complete Email Capture Across All Platforms. Shield captures email from Microsoft Exchange, Microsoft 365 and Office 365, Gmail and Google Workspace, and other corporate email platforms — ingesting inbound, outbound, and internal messages, forwarded and replied chains, calendar invitations, meeting requests, and task-related communications, alongside all file attachments and every metadata field. All data is ingested in full, with zero data loss, across all supported email platforms and deployment models, including on-premises, cloud, and hybrid environments.
Full Metadata Preservation. Shield retains and enriches the complete email metadata layer — including sender and recipient identifiers, distribution list memberships, timestamps, message IDs, thread identifiers, delivery receipts, read receipts, and routing headers. This metadata is preserved in its original form, made fully searchable, and stored as part of the immutable compliance record — ensuring that thread reconstruction, regulatory examination responses, and eDiscovery productions are accurate and legally defensible.
Attachment Indexing and Search. Shield indexes and makes searchable the content of email attachments — including documents, spreadsheets, presentations, and PDFs — enabling compliance teams and investigators to search across both message text and attachment content in a single unified workflow. Attachment content is archived alongside the messages it accompanies, preserving the complete email record rather than storing attachments as opaque binary files.
Immutable, Audit-Ready Archive. All email data captured by Shield is stored in a tamper-evident, WORM-compliant archive with a complete audit trail of every access and action taken on the record. Data is indexed for rapid search and retrieval, supporting regulatory examination responses, eDiscovery requests, and internal investigations. Retention periods are fully configurable to meet jurisdiction-specific requirements — including the six-year standard under SEC Rules 17a-3 and 17a-4, the five-to-seven-year requirements under MiFID II and MAR, and the five-year requirements under CFTC Regulation 1.35.
Out-of-the-Box AI Surveillance Models. Shield ships with pre-configured AI surveillance models for email, targeting behaviours including market manipulation, MNPI sharing, information leakage, front-running, conflicts of interest, inappropriate client communications, and personal misconduct — calibrated to the specific language patterns of financial services email communications. Models can be customised to reflect a firm’s specific risk appetite, restricted lists, and internal policy requirements.
Unified Cross-Channel Surveillance. Email does not exist in isolation. The same employees communicating over email are also using Bloomberg IB, Microsoft Teams, Symphony, voice, and mobile — often about the same trades, clients, and decisions. Shield ingests email into the same unified compliance platform as every other channel, enabling compliance teams to correlate email with chat, voice, trade data, and all other sources. This cross-channel context is essential for accurate misconduct detection, complete trade reconstruction, and defensible regulatory responses.
Data Governance and Chain of Custody. Shield’s Email connector preserves a complete, verifiable chain of custody from capture through archiving and retrieval across all supported email platforms. Every stage of data handling is logged, auditable, and reportable — giving compliance officers and legal teams the confidence that email records are admissible, complete, and unaltered throughout their lifecycle.
Regulatory Coverage
Email communications are classified as business records subject to capture, retention, and surveillance requirements across the most comprehensive range of regulatory frameworks in financial services. The Shield Email connector supports compliance with:
- SEC Rules 17a-3 and 17a-4 — requiring broker-dealers to capture, preserve, and produce records of all communications related to their business, stored in WORM-compliant, non-rewriteable format with an audit trail, for a minimum of six years. Email was the primary channel for which these rules were originally developed, and remains at the core of SEC and FINRA recordkeeping examinations.
- FINRA Rules 4511 and 3110 — requiring member firms to archive all communications relating to their business as such — with written supervisory procedures, supervision requirements, and full audit trail capability in place. Email supervision is a foundational component of FINRA’s examination programme.
- MiFID II Article 16(7) and Market Abuse Regulation (MAR) — requiring investment firms to record and retain electronic communications related to orders and transactions for a minimum of five years, with trade reconstruction capability within three days, and to monitor communications for indicators of insider trading, front-running, and market manipulation. Email is one of the primary channels for trade-related correspondence under MiFID II.
- CFTC Regulation 1.35 and 17 CFR § 23.202 — requiring swap dealers, major swap participants, and futures commission merchants to retain records of all communications relating to commodity interests and swap transactions as part of a complete audit trail for trade reconstruction, including email communications.
- FCA Rules (SYSC 10A and MAR) — requiring FCA-regulated firms to record and retain relevant electronic communications for a minimum of five years, and to implement effective surveillance arrangements to detect and prevent market abuse.
- SEC Investment Adviser Act Rules 204-2 — requiring registered investment advisers to maintain records of client communications and advisory correspondence — directly applicable to email in wealth management, advisory, and asset management contexts.
- GDPR and applicable data privacy regulations — Shield’s architecture supports data residency requirements and privacy-compliant data handling across jurisdictions, enabling firms to meet GDPR and equivalent obligations for email data alongside their financial services recordkeeping requirements.
Other Related Connectors
Shield’s connector portfolio spans the full range of eComms channels and trading platforms used across regulated financial institutions. All connectors feed into a single unified compliance platform — so email data is always reviewed in the context of every other channel your workforce uses.
- Microsoft Exchange
- Office 365
- Gmail
- Bloomberg IB and Bloomberg Mail
- Microsoft Teams
- Microsoft Teams Chat
- Symphony
- ICE Chat
- FX Connect
- WhatsApp Business
- Voice and Turret
- Mobile (SMS/MMS)
- SMTP Mail
Frequently Asked Questions
Does Shield capture email attachments as well as message text?
Yes. Shield ingests and indexes email attachments — including documents, spreadsheets, presentations, and PDFs — alongside message text, making both the message content and attachment content searchable in a unified workflow. Attachment content is archived with the messages it accompanies, preserving the complete email record.
Which regulations does the Shield Email connector help firms comply with?
The Shield Email connector supports compliance with SEC Rules 17a-3 and 17a-4, FINRA Rules 4511 and 3110, MiFID II, Market Abuse Regulation (MAR), CFTC Regulation 1.35 and 17 CFR § 23.202, FCA SYSC 10A, SEC Investment Adviser Act Rules 204-2, and applicable data privacy regulations including GDPR.
How does Shield handle email thread reconstruction for trade reconstruction purposes?
Shield preserves the full thread structure of every email conversation — including forwarded chains, inline replies, and attachment histories — enabling compliance teams and regulators to reconstruct the complete sequence of communications surrounding any trade, order, or client instruction. This thread-level fidelity is essential for meeting the trade reconstruction requirements of MiFID II, Dodd-Frank, and CFTC regulations.
Can email data be reviewed alongside Bloomberg IB, Teams, and other channels during an investigation?
Yes, and this is central to effective email compliance. Business interactions frequently span multiple channels — a negotiation may begin on Bloomberg IB, be confirmed via email, and followed up on Teams or voice. Shield ingests email into the same unified compliance archive as every other channel, enabling compliance teams to reconstruct the complete sequence of a business interaction across all platforms in a single workflow.
How should firms approach data residency and GDPR requirements for email?
Email data is typically among the largest volumes of personal data held by regulated firms, and GDPR obligations — including lawful basis for retention, data subject access rights, and retention limitation — apply to email data alongside financial services recordkeeping requirements. Shield’s architecture supports configurable retention periods and data residency controls across all supported email platforms, enabling firms to meet jurisdiction-specific requirements without compromising on surveillance or retrieval capability.