Security & trust
The safest claim in email is the one you can check. Here's what inxo does and how you can see it.
Scoped access, proven.
Access is scoped to the mailboxes you choose — never tenant-wide. Before a connection activates, a verification step shows you the evidence: which mailbox, which permissions, and nothing else. Disconnecting stops the sync, tears down our access and erases what we hold, and records exactly what was removed — the one remaining step, removing the scoped grant itself, belongs to your Microsoft administrator, and we tell you so
Approval by default.
No reply leaves without an authorized approval. Each approval is recorded — who approved, which draft version, and when. Agent auto-send is designed as an explicit, audited, per-workspace policy — never a default. Coming
approval 01a0867d-1ef0-7d98-a873-db16db2ce49f approver 01a08682-c440-7c1a-9daa-668075d7c7d2 (reviewer, Brand A) draft 01a0867c-8e68-718d-8045-320ae2141d63 v1 approved_at 2026-09-02T14:07:31Z provenance human_console auto_send: false sources ▸ pricing-2026.pdf ▸ billing-faq.md sent →| provider_message_id AAMkAD… reconciled ✓
Drafting under hard rules.
Replies stay transactional in character. Personal data beyond what the writer provided is blocked on every send — that one is a wall. Promotional content, promised fixes and timelines are steered and measured, with your reviewer as the control; we would rather tell you which is which than let you assume the wall is everywhere. Bounces and auto-replies don't generate drafts. When neither the conversation nor your knowledge base contains the answer, inxo is instructed not to invent one, and the sources on the draft show you what it did use.
Inbound mail and your documents are data, not instructions.
Inbound mail — including text addressed to the AI — and the documents in your knowledge base are both treated as material for drafting a reply, never as commands. A document cannot change how inxo behaves. And underneath it, the rule that doesn't depend on the model being right: nothing sends without approval.
Your knowledge base is yours.
Each knowledge base belongs to one workspace. It is never used to train models, never shared across accounts, and deleted with the last mailbox connection for that controller.
Your data.
inxo acts as a processor for the mail it handles. Draft retention is bounded; mail and drafts are deleted when a mailbox is disconnected. Audit records — drafts, approvals, sends — are retained in tamper-evident form. AI-generated content is marked as such.
When something goes wrong.
Incidents are severity-classified and handled through a defined process. Where your customers' mail may be affected we notify you without undue delay, because you are the controller and the regulatory clock is yours to run — we give you what you need to run it.