Security

Minimum data.Narrowest permissions.By design.

Built on trust

Four guarantees, by design.

01 · Scope

Client-only scope

We watch only the threads on your watchlist. Your bank, your family, your vendors, never touched.

0 emails read outside watchlist
02 · Security

Bank-grade encryption

AES-256 at rest. TLS 1.3 in transit. SOC 2-aligned controls. GDPR compliant from day one.

AES-256 · TLS 1.3 · SOC 2
03 · Invisibility

Client never knows

Replies send from your inbox, in your voice. No third-party branding. No fingerprints. Ever.

Sent from your address
04 · Portability

Your data leaves with you

Cancel any time. We send you a 12-month report of every signal we caught and every commission we protected, yours to keep.

Full export · 12-mo report
Access model

The least-privilege table.

Exactly what we can and cannot do, written in your provider's permission terms, not ours.

CapabilityClawbackVault
Read email metadataWatchlist threads only
Read email contentIn memory · never persisted
Send emailNever autonomously
Modify or delete emailNever
Access non-watchlist threadsBlocked at first filter
Trigger actions without your inputNever
Revoke access at any timeOne click in your provider
Data lifecycle

Process the signal. Drop the message.

In memory

Email bodies are read into volatile memory, scored, and discarded within seconds. They never hit disk.

At rest

Only signal metadata, sender, timestamp, signal type, risk band, is stored. AES-256 encrypted.

In transit

TLS 1.3 on every connection between your inbox provider, our service, and your devices.

Frequently asked

The detail brokers actually ask about.

What happens if I remove a client from the watchlist?

They become invisible to the system immediately. Existing signal metadata is purged within 24 hours.

Where is data stored?

EU data residency by default (Frankfurt). Optional US region for North American firms.

Do you train AI models on my data?

No. Your inbox content is never used to train shared or external models, full stop.

What's your incident response window?

Confirmed incidents are disclosed to affected customers within 24 hours, with a full root-cause report within 7 days.