Security
Your email is your paper trail — rate confirmations, claims, and carrier agreements. Here is how we protect it.
Tenant isolation
Every record is scoped to your organization, and mailbox-level permissions control which team members can read each inbox.
Draft-only AI
AI Mailbox never sends on its own: it creates reply drafts, and your team decides what gets sent from Gmail or Outlook. Programmatic sending exists only through the Platform API, gated behind explicit send scopes that an organization administrator provisions.
No third-party model training
Customer email content is processed to provide the service and is not used to train third-party AI models.
Encrypted credentials
OAuth credentials are stored server-side and encrypted. Raw tokens are never exposed in the UI.
Data minimization
We store the email content your team works with — not transport machinery. Routing chains and signature blobs are stripped at ingest, while authentication verdicts are retained for dispute evidence.
Verified webhooks
Gmail Pub/Sub and Outlook Graph notifications are authenticated before processing.
Independent assessment
Freightbox has been independently assessed under CASA Tier 2 (App Defense Alliance, Web App Profile) by TAC Security, covering our production application and API. All assessment checks passed (August 2026); the Letter of Validation is being issued and submitted to Google.
Responsible disclosure
Security researchers can report issues to security@getfreightbox.com. Details, scope, and safe-harbor terms are published in the app’s vulnerability disclosure policy.
Data deletion
Organizations can request full erasure of their data. See the data deletion process and our privacy policy.