Security & trust

The safest claim in email is the one you can check. Here's what inxo does and how you can see it.

Scoped access, proven.

Access is scoped to the mailboxes you choose — never tenant-wide. Before a connection activates, a verification step shows you the evidence: which mailbox, which permissions, and nothing else. Disconnecting stops the sync, tears down our access and erases what we hold, and records exactly what was removed — the one remaining step, removing the scoped grant itself, belongs to your Microsoft administrator, and we tell you so

Console — connection verification evidence

Approval by default.

No reply leaves without an authorized approval. Each approval is recorded — who approved, which draft version, and when. Agent auto-send is designed as an explicit, audited, per-workspace policy — never a default. Coming

approval      01a0867d-1ef0-7d98-a873-db16db2ce49f
approver      01a08682-c440-7c1a-9daa-668075d7c7d2  (reviewer, Brand A)
draft         01a0867c-8e68-718d-8045-320ae2141d63  v1
approved_at   2026-09-02T14:07:31Z
provenance    human_console   auto_send: false
sources       ▸ pricing-2026.pdf  ▸ billing-faq.md
sent          →|  provider_message_id AAMkAD…  reconciled ✓

Drafting under hard rules.

Replies stay transactional in character. Personal data beyond what the writer provided is blocked on every send — that one is a wall. Promotional content, promised fixes and timelines are steered and measured, with your reviewer as the control; we would rather tell you which is which than let you assume the wall is everywhere. Bounces and auto-replies don't generate drafts. When neither the conversation nor your knowledge base contains the answer, inxo is instructed not to invent one, and the sources on the draft show you what it did use.

Inbound mail and your documents are data, not instructions.

Inbound mail — including text addressed to the AI — and the documents in your knowledge base are both treated as material for drafting a reply, never as commands. A document cannot change how inxo behaves. And underneath it, the rule that doesn't depend on the model being right: nothing sends without approval.

Your knowledge base is yours.

Each knowledge base belongs to one workspace. It is never used to train models, never shared across accounts, and deleted with the last mailbox connection for that controller.

Your data.

inxo acts as a processor for the mail it handles. Draft retention is bounded; mail and drafts are deleted when a mailbox is disconnected. Audit records — drafts, approvals, sends — are retained in tamper-evident form. AI-generated content is marked as such.

When something goes wrong.

Incidents are severity-classified and handled through a defined process. Where your customers' mail may be affected we notify you without undue delay, because you are the controller and the regulatory clock is yours to run — we give you what you need to run it.