Email compliance software controls, in plain language
The page a RevOps lead reads before the demo call. No badge wall, no certification we have not earned, and an explicit no wherever the honest answer is no.
What is processed, and what is not kept
- Prospect data you connect
- CRM records, notes and the account pages you point the agent at. It is processed to research the account and to write the draft, and it is stored so the claim ledger can show which source a claim came from at send time. It is yours, you export it, you delete it.
- Drafts, ledgers and verdicts
- Kept with the send, because the audit trail is the product. Export windows follow the plan: 30 days on Solo, 12 months on Team, scheduled and unlimited on Scale, and to your own bucket on Enterprise.
- Model training
- Prospect data is never used to train a foundation model, and nothing from one account is used to improve another. The claim library learns only inside your account, only from statements a person there approved explicitly.
- A shared contact pool
- There is not one. Customer accounts are not pooled into a database that gets resold as leads, because that is how a supplier ends up competing with its own customers for the same inbox.
- This website
- The signup stores an email address, how you arrived, and the IP and user agent for abuse triage. The demo sends what you typed to the model provider to generate the draft and does not store it against your identity. Details are in the privacy policy.
The controls you set, and the agent cannot unset
- Per mailbox daily cap
- A number you type. The queue enforces it and the agent has no override, no burst mode and no catch up after a quiet day. When the ceiling is reached the queue waits for tomorrow.
- Per domain caps
- On Enterprise the ceiling is set at the domain level as well, so one team or one client cannot spend another one's headroom.
- Approval policy
- Approve everything, approve only what the ledger flagged, or spot check. On Enterprise the policy is enforced by role, so an individual cannot turn their own approvals off.
- Hold on unverified claims
- A draft carrying a claim with no source does not enter the send queue. There is no setting that makes it send anyway, and that is deliberate.
- Suppression
- Checked at draft time rather than at send time, so a suppressed contact never reaches a queue. Lists are per domain, importable and writable by API.
- One click unsubscribe and the address block
- Present on every message, checked before the draft can clear. A draft missing either one fails the compliance check by definition.
- Stop
- One control stops the sequence, the queue and every scheduled follow up. Replies stop their own thread automatically.
Access, identity and administration
- SSO and SAML
- On Enterprise. Your identity provider owns who gets in and who stops getting in.
- SCIM provisioning
- On Enterprise. Joiners and leavers are handled where the rest of your joiners and leavers are handled.
- Roles
- Separate the person who writes, the person who approves and the person who sets the cap. On Enterprise those separations are enforced rather than agreed.
- Audit export
- Every send with its draft, its claim ledger, its verdict and the source line behind each cited claim, as they stood at the moment it went out.
- Data location
- Regional hosting, including an EU region, on Enterprise.
Subprocessors, by category
- Hosting and database
- One infrastructure provider runs the application and its database.
- Email delivery
- One provider delivers transactional mail from our own domain, including the confirmation code for the signup on this site.
- Language model
- One hosted model provider generates drafts, server side. The key never reaches a browser and prospect data is not used for training.
- The current list
- Named, with what each one does and where it operates, on request. Write to [email protected] with "Subprocessor list" in the subject and it is sent back by a person.
Paperwork, and what we do not claim
- DPA
- Available on request, and signed as standard on Enterprise.
- Security review
- We answer questionnaires and we will talk to your security team. On Enterprise it is part of the agreement rather than a favour.
- Certifications
- We are not going to put a badge on this page that we have not earned. Where you need a specific attestation, ask, and the answer will be a date or a no rather than a logo.
- Legal advice
- None of this is legal advice. The product enforces mechanical requirements, an unsubscribe line, an address block, a suppression check, a cap. It cannot establish that you had a lawful basis to contact somebody, and it does not pretend to.
- Security contact
- [email protected]. If you have found something, write to that address and it reaches a person the same day.
The controls above are what makes the rest of the site true. The workflow they wrap is on ai sales agent, the capability list is on sales automation software, and the plan each control belongs to is on AI SDR software pricing.
Bring this page to your security team.
Everything above is a control you set or a record you can export. If your review needs an answer that is not here, write to us and you get a date or a no, not a logo.
Your data stays yours. Prospect data is never used to train a model. Nothing is charged today.