Yes. InboxPilot is SOC 2 Type II certified and GDPR compliant, encrypts data in transit and at rest, connects to your inbox via scoped OAuth permissions, and is monitored around the clock with regular third-party penetration testing.
InboxPilot is SOC 2 Type II certified and GDPR compliant. Our SOC 2 report and additional security documentation are available on request for security reviews.
No. Your email is used only to perform the work you ask of it. It is never used to train shared or third-party AI models. What's yours stays yours.
No. InboxPilot drafts replies for you to review and send. Auto-send only ever runs on rules you explicitly configure and enable, so you stay in control.
InboxPilot connects through OAuth with the minimum scopes required to triage, draft, and label your email. Permissions are granular and you can revoke access at any time from your Google or Microsoft account.
All data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher, using industry-standard algorithms.
Yes. InboxPilot is built to meet GDPR requirements, including lawful processing, data minimization, transparency, and your right to access and delete your data.
Yes. InboxPilot offers role-based access, SSO, scoped permissions, audit logging, and a documented sub-processor list, with security reviews available for enterprise procurement.
At any time. Disconnect your inbox to immediately revoke access, and request full deletion of your data whenever you choose.