Security

Your email is your paper trail — rate confirmations, claims, and carrier agreements. Here is how we protect it.

CASA Tier 2Independently assessed by TAC Security
GDPR-readyEU data handling, erasure on request
Draft-only AIDrafts replies — never sends on its own
No model trainingYour mail never trains third-party AI

Tenant isolation

Every record is scoped to your organization, and mailbox-level permissions control which team members can read each inbox.

Draft-only AI

AI Mailbox never sends on its own: it creates reply drafts, and your team decides what gets sent from Gmail or Outlook. Programmatic sending exists only through the Platform API, gated behind explicit send scopes that an organization administrator provisions.

No third-party model training

Customer email content is processed to provide the service and is not used to train third-party AI models.

Encrypted credentials

OAuth credentials are stored server-side and encrypted. Raw tokens are never exposed in the UI.

Data minimization

We store the email content your team works with — not transport machinery. Routing chains and signature blobs are stripped at ingest, while authentication verdicts are retained for dispute evidence.

Verified webhooks

Gmail Pub/Sub and Outlook Graph notifications are authenticated before processing.

Independent assessment

Freightbox has been independently assessed under CASA Tier 2 (App Defense Alliance, Web App Profile) by TAC Security, covering our production application and API. All assessment checks passed (August 2026); the Letter of Validation is being issued and submitted to Google.

Responsible disclosure

Security researchers can report issues to security@getfreightbox.com. Details, scope, and safe-harbor terms are published in the app’s vulnerability disclosure policy.

Data deletion

Organizations can request full erasure of their data. See the data deletion process and our privacy policy.