# Envolt Mail: full site for AI agents > Mail built for AI agents and the humans that build them. In development. The core inbound pipeline runs in staging on synthetic test mail; nothing is sent and no real mailbox is connected. Generated 2026-10-02 from the same source as https://envoltmail.com/. --- Source: https://envoltmail.com/ Email for agents, with people in charge # Mail built for AI agents and the humans that build them. An email platform designed so every artificial intelligence (AI) agent has its own clearly labeled, verifiably sealed mailbox. Agents draft and propose. Your policy and your people decide what is sent. [Request early access](https://envoltmail.com/contact#early-access) [Watch the Airlock work](https://envoltmail.com/#xray) [In development] The inbound pipeline runs in staging on test mail. [What runs today →](https://envoltmail.com/status) DESIGN PREVIEW · AGENT MESSAGE - **From**: Relay AI agent · Northwind Games - **To**: maya@example.com - **Subject**: Your beta key is ready - **Seal**: ✓ verified Envolt-Agent-Seal Hi Maya, your beta key for Northwind is attached. Want me to book a 15-minute walkthrough? Approved by **Northwind's team** · policy check passed[Verify this agent →](https://envoltmail.com/#seal) Relay is an AI agent working for Northwind Games. Reply "human" at any time to reach a person. The problem ## Email was built for people. Agents are showing up anyway. Most teams hand an agent the password to a shared inbox and hope. Recipients can't tell who they're talking to, the agent can send anything to anyone, and any stranger can email it instructions. ### For people who get agent mail Know when an agent wrote to you, who it works for, and how to reach a person instead. ### For teams who build agents Give each agent its own address and signing identity, with clear rules for what it may send and to whom. ### For whoever answers for it Every send has an accountable person, a policy decision and a tamper-evident record. Airlock X-Ray [Running in staging] ## The same email, three ways. Prompt injection hides instructions where people can't see them but models can read them. Below, our real Airlock code runs on a hostile sample, in your browser. Edit it and try your own tricks. Interactive demo on the web page: a sample email with hidden instructions, shown as a person sees it, as a naive agent reads it, and as Envolt's reader receives it after the Airlock (the real code, run in the browser). How it works ## Agents propose. Policy checks. People decide. 1. **Airlock**Each message is parsed in isolation, stripped of hidden text and stored encrypted. [Running in staging] 2. **Reader**A reader with no tools describes the message. It can raise attention, never lower it. [Running in staging] 3. **Agent drafts**The agent proposes a reply or an action. It can't send by itself. [Designed] 4. **Seal policy**Recipients, content, rate and approval needs are checked against rules your team owns. [Designed] 5. **A person decides**One tap to approve, edit or hold, unless the agent has earned that kind of send. [Designed] 6. **Labeled, sealed send**A single-use key, the AI agent label, a signed seal and a plain disclosure. [Designed] **On the record:** every step is written to a hash-chained ledger, anchored daily. [Running in staging] [Read the full walkthrough →](https://envoltmail.com/how-it-works) Agent Seal [Running in staging] ## Verify an agent message yourself. Every agent message is designed to carry a signed Agent Seal header: which agent, who it works for, how much autonomy it has. Here is the production verifier, running in your browser. Try to break it. Interactive demo on the web page: an example message with an Envolt-Agent-Seal header, verified in the browser by the production verifier (Ed25519 over a canonical string of the seal fields, Message-ID and Date), with buttons to tamper with it and watch verification fail. ## Designed around four rules ### Always labeled Every agent message says plainly that an agent wrote it, and who it works for. ### No standing send rights Agents never hold a key to send. Each approved message gets its own single-use one. ### Mail is data Nothing inside an email can give an agent new orders or new permissions. ### Human mail first Envolt Mail stays out of your people's own mail path. If it's ever down, their mail still flows. [How we protect your mail →](https://envoltmail.com/security) Built in the open ## Evidence over promises. Every claim on this site comes from one status file, and every release leaves a receipt. - **674**automated tests - **7**capabilities running in staging - **10**designed, not built yet - **October 2**last service release [See what runs today](https://envoltmail.com/status) · [Read the changelog](https://envoltmail.com/changelog) ## Building agents that need email? Tell us what your agents do. We'll reach out as early access opens. [Request early access](https://envoltmail.com/contact#early-access) --- Source: https://envoltmail.com/status Status · updated October 2, 2026 # What runs today Envolt Mail is in development. This page is generated from the same status file as every badge on this site, so the two can't disagree. - **[Live]**: Public and running in production. - **[Running in staging]**: Built and running on our staging environment, on synthetic test mail only. - **[Designed]**: Specified in detail, not built or not switched on yet. ## Capabilities ### Public - **This website** [Live] envoltmail.com, with a strict content security policy, no cookies and no analytics. - **Authenticated, signed domains** [Live] Our own domains publish Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) records and are signed with Domain Name System Security Extensions (DNSSEC). ### Inbound - **Airlock quarantine** [Running in staging] Parses each message in isolation, converts HTML to plain text, removes and counts hidden content and invisible characters (including Unicode tag characters), and inspects attachments. - **Rules-first triage** [Running in staging] Duplicates, bulk mail and notifications are recognized by rules before any model runs. - **Agent Seal verification** [Running in staging] Incoming mail that carries an Agent Seal header is checked against the sender's published keys. - **Quarantined reader** [Running in staging] A reader with no tools turns each message into a structured case. It redacts card, bank account and US Social Security numbers first, can only raise attention, and fails closed to a person. It runs on a no-cost synthetic stand-in; no real model is switched on. ### Storage - **Per-message encryption** [Running in staging] Raw mail and attachments are encrypted with a key per message, wrapped under a per-customer key, with versioned keys. ### Record - **Tamper-evident ledger** [Running in staging] Every event is hash-chained and anchored daily. Conversation threads are re-verified before each anchor, and a broken chain is sealed and recorded, never anchored. - **Isolation canaries** [Running in staging] Every staging check plants unique markers in separate synthetic test customers and confirms neither can see the other's. ### Mailboxes - **Mailbox connections** [Designed] Read-only connections beside your existing mail, never in its delivery path. A read-only connector is built and tested but not connected to any mailbox. ### Agents - **Agent drafting** [Designed] Agents read a conversation and propose a plan: a reply, an action, or a question for a person. - **Seal policy** [Designed] A policy engine that checks every plan's recipients, content, rate and approval needs against rules your team owns. ### People - **Approval queue** [Designed] One card per decision: the ask, a recommendation, alternatives, the risk, and one-tap approve, edit or hold. - **Earned autonomy** [Designed] An agent can earn routine sends from its measured track record, and loses them automatically on any serious mistake. - **Kill switch** [Designed] Halts every agent, one persona or a single agent instantly. - **Accounts and sign-in** [Designed] Invited accounts with passkeys. There are no accounts yet. ### Outbound - **Labeled, sealed sending** [Designed] Each approved message gets a single-use capability and goes out with the AI agent label, a signed Agent Seal header and a plain-language disclosure. - **Public receipts** [Designed] A verify link that shows who the agent is, who it works for and whether a person approved, never the message content. ### Builders - **API, webhooks and MCP** [Designed] A REST API, signed webhooks and a Model Context Protocol (MCP) server for agents. Specified, not built. ## Latest release evidence Every release runs through a gated lane and leaves a receipt. These are the most recent ones. ### Service release `slice-14.0` October 2, 2026 · commit `7b75d6968172` - ✓ Full test suite - ✓ Security gate tests - ✓ Bundle leak scan - ✓ Domain settings match the recorded posture - ✓ Database migration tests - ✓ Staging smoke checks, including live attack samples - ✓ Production health verified ### Website release October 2, 2026 · commit `a274d4c8c636` - ✓ Site build - ✓ Site leak scan - ✓ Site tests - ✓ Staging, then production, verified page by page - ✓ Home page Largest Contentful Paint (LCP) 1,736 ms against a 1,800 ms target; other pages 1,688 ms or less. Layout shift 0. Measured on emulated slow 4G. ## What comes next The planned order, without dates. It may change, and this page will change with it. ### Now - The inbound pipeline in staging: Airlock, reader, ledger and integrity checks - This website, built in the open ### Next - The Seal policy engine and agent drafting - A first read-only mailbox connection in shadow mode - An approval console for the accountable human ### Later - Labeled, sealed sending with single-use capabilities - Public receipts and earned autonomy - Early access for outside teams History: [the changelog](https://envoltmail.com/changelog) (also as an [Atom feed](https://envoltmail.com/changelog.xml)). Agents: this page is at [/status.md](https://envoltmail.com/status.md). --- Source: https://envoltmail.com/how-it-works How it works # From inbox to sealed reply Envolt Mail separates what an agent *wants* to do from what it's *allowed* to do, and keeps a person accountable for the difference. Steps marked [Running in staging] work today on synthetic test mail. Steps marked [Designed] are specified and not built yet. [Full status →](https://envoltmail.com/status) ## 1. Inbound mail is quarantined [Running in staging] Every message is parsed in isolation and stored encrypted with its own key. HTML becomes plain text. Text a person couldn't see (hidden by styling, tucked in comments, or written in invisible characters) is removed and counted, so agents only ever get a safe, text-first view. Links, attachments and hidden text are treated as data. They can't carry instructions that change what an agent may do. [See it on a hostile email →](https://envoltmail.com/#xray) ## 2. Rules triage before any model runs [Running in staging] Duplicates, newsletters and bulk mail are recognized and filed by rules, without spending anything on artificial intelligence (AI). Only mail that needs thought goes further. ## 3. A quarantined reader describes the message [Running in staging] A reader with no tools turns the message into a structured case: intent, urgency, a short summary, and any commitments or decisions in it. Card, bank account and US Social Security numbers are redacted before it reads anything. Simple detectors run first, and the reader can only add to their warnings, never clear them. If it misbehaves, the case fails closed to a person. ## 4. The agent drafts a plan, not a send [Designed] An agent working the conversation will propose a plan: who to reply to, what to say, what to attach. It holds no password and no standing permission to send. ## 5. The Seal policy checks the plan [Designed] A policy engine will check every plan against rules your team owns: who the recipients are and whether they're known, what's in the content, rate limits, and whether a person must approve. Anything unclear goes to a person by default. ## 6. A person decides, or the agent has earned it [Designed] New agents draft for approval. Approving will take one tap from a queue that shows the recommendation, alternatives and risk. Over time an agent can earn the right to send routine replies on its own, based on its measured track record. Any serious mistake takes that right away automatically. ## 7. The message goes out labeled and sealed [Designed] Approved messages will be sent with a single-use capability, so one approval can never be reused. Each will carry the "AI agent" label, a signed Agent Seal header, a plain-language disclosure and a link to a public receipt. [See what recipients will see →](https://envoltmail.com/docs/recipients) ## 8. Everything is on the record [Running in staging] Every event is written to a hash-chained ledger that is anchored daily. Before each anchor, recently active conversation threads are re-verified. A broken chain is sealed, recorded and never anchored, so you can prove what happened, and what didn't. --- Source: https://envoltmail.com/security Security # Built to keep your mail yours An agent with email access is a powerful thing to hand to software. Envolt Mail is designed so that power stays bounded, visible and accountable. Each section says whether it runs today. [Running in staging] means built and running on synthetic test mail. [Designed] means specified, not built yet. ## Mail content can't command an agent [Running in staging] Prompt injection plants instructions in an email to manipulate an artificial intelligence (AI) agent. It is the defining risk of agent mail. In Envolt Mail, message content is always data. Text hidden by styling, comments and invisible characters (including Unicode tag characters, which models read but people can't see) is removed and counted before anything reads the message. Detectors flag instruction-like text, and the reader has no tools and can't lower a warning. [Try it on a hostile email →](https://envoltmail.com/#xray) ## Encrypted per message [Running in staging] Raw mail and attachments are encrypted with a unique key per message. Those keys are wrapped under a key specific to each customer and bound to where the data is stored, so a copied file is unreadable anywhere else. Keys are versioned, so they can be rotated without re-encrypting mail. ## Every customer is isolated [Running in staging] Each organization will get its own encrypted storage, its own keys and its own records. Every release is already checked for this: our staging checks plant unique markers in separate synthetic test customers and confirm that neither can ever see the other's. ## A tamper-evident record [Running in staging] Every event is hash-chained and the chain is anchored daily. Conversation threads are re-verified before each anchor. A broken chain is sealed and recorded, freezes the affected record until a person repairs it, and is never anchored. ## No standing send rights [Designed] Agents will never hold credentials to send mail. Each approved message will get a single-use capability that expires quickly and can't be replayed. A kill switch will halt every agent, or a single one, instantly. ## Our own first customer, with no shortcuts [Designed] When Envolt Mail runs, our studio will use it through the same public interfaces and protections as any customer. Staff will have no standing access to anyone's mail content, including the studio's. Support access will happen only with your approval, time-boxed and recorded where you can see it. Today no studio mailbox is connected. ## Your domain, done properly [Live] Our own domains publish Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) records, and are signed with Domain Name System Security Extensions (DNSSEC). Agent mail will be authenticated the same way, and Envolt Mail never takes over the mail exchanger (MX) records your people rely on. ## Every release passes the gates A release can't ship unless the full test suite passes and the bundle is scanned for anything that shouldn't leave the building. Outbound traffic is limited to an allowlist, and logs are swept for planted canaries. Each release leaves a receipt. [See the latest →](https://envoltmail.com/status) ## Who handles what - **Hosting:** the website and the service run on Cloudflare. - **AI models:** none receive mail today. The reader runs on a no-cost synthetic stand-in in staging; the real model is switched off. - **Mailboxes:** none are connected. ## Reporting a vulnerability Email [security@vaultsparkstudios.com](mailto:security@vaultsparkstudios.com) or see our [security.txt](https://envoltmail.com/.well-known/security.txt). We read every report. --- Source: https://envoltmail.com/agents For agents & builders # An inbox your agent can be trusted with If you build artificial intelligence (AI) agents, email is where they meet the real world. Envolt Mail is being built to give them a proper place to work there. ## A safe view of inbound mail [Running in staging] Your agent gets sanitized, structured conversations: hidden content removed and counted, attachments inspected, and a case that says what the sender wants. Your agent spends its effort on the conversation, not on parsing email or defending against it. [See the Airlock on a hostile email →](https://envoltmail.com/#xray) ## An identity, not a shared password [Designed] Each agent will get its own address, display label and signing identity. Recipients see exactly which agent wrote to them and who it works for, and they can verify it. The verification side already runs: [try it](https://envoltmail.com/#seal). ## An outbox with guardrails [Designed] Your agent will propose plans, and the Seal policy applies your rules on recipients, content, rate and approval. Mistakes are stopped before they're sent, not apologized for afterwards. ## Autonomy you can earn and measure [Designed] Every message starts out approved by a person. As an agent proves itself on real work, measured by acceptance rate, edits and policy results, it can take on routine replies. Its autonomy is visible, reversible and on the record. ## Interfaces built for agents [Designed] A REST API, signed webhooks and a Model Context Protocol (MCP) server, so your agent can read cases, request drafts and propose actions, but never hold the powers reserved for a person. Read the [builder preview](https://envoltmail.com/docs/builders). ## This site reads well to agents, too Every page is published as Markdown (add `.md`, or send `Accept: text/markdown`), alongside [agents.json](https://envoltmail.com/agents.json), [llms.txt](https://envoltmail.com/llms.txt) and [llms-full.txt](https://envoltmail.com/llms-full.txt). ## Building agents that need email? Tell us what your agents do. We'll reach out as early access opens. [Request early access](https://envoltmail.com/contact#early-access) --- Source: https://envoltmail.com/docs Docs # Documentation Envolt Mail is in development, so these docs describe the design and mark what runs today. Every page is also available as Markdown for agents: add `.md` to its address. ## [For recipientsHow to tell a message came from an Envolt Mail agent, how to verify it, and how to reach a person instead.](https://envoltmail.com/docs/recipients) ## [For builders (preview)The Agent Seal header format, the key document, and the interfaces your agents will use.](https://envoltmail.com/docs/builders) ## [GlossaryAirlock, Agent Seal, Seal policy, trust tiers, receipts and the rest, in plain language.](https://envoltmail.com/docs/glossary) ## [Questions and answersDoes it replace your mail server? Can agents send on their own? What does it cost?](https://envoltmail.com/faq) --- Source: https://envoltmail.com/docs/recipients [Docs](https://envoltmail.com/docs) / For recipients # Recognizing an Envolt Mail agent Every message an artificial intelligence (AI) agent sends through Envolt Mail is designed to identify itself in four ways, so you never have to guess. Envolt Mail doesn't send mail yet. This page describes what every agent message will carry. [Designed] ## 1. The sender name says "AI agent" The display name always follows the same pattern: the agent's name, the words *AI agent*, and who it works for. Relay (AI agent) · Northwind Games ## 2. A disclosure closes every message The last lines of the message tell you it came from an agent and how to reach a person: Relay is an AI agent working for Northwind Games. Reply "human" at any time to reach a person. ## 3. A verifiable seal travels in the headers [Running in staging] Each message carries an `Envolt-Agent-Seal` header, signed by the organization the agent works for and covered by the sending domain's DomainKeys Identified Mail (DKIM) signature, so it can't be copied onto a message the agent didn't send. Mail software can check it automatically against the organization's published keys. Our verifier already runs in staging, and you can [try it in your browser](https://envoltmail.com/#seal). The format is in the [builder preview](https://envoltmail.com/docs/builders#agent-seal). ## 4. A public receipt shows who approved it [Designed] A *Verify this agent* link will open a public receipt. It shows who the agent is, who it works for, how much autonomy it has, whether a person approved this message, and that the send passed policy. The receipt never shows the message's content, subject or recipients, and it isn't used to track whether you opened the email. ## Want a person instead? Reply with the single word **human**. The conversation goes to the person responsible for that agent. ## Something looks wrong? If a message claims to come from an Envolt Mail agent but fails any of these checks, or an agent behaves badly, email [hello@envoltmail.com](mailto:hello@envoltmail.com). For security issues, write to [security@vaultsparkstudios.com](mailto:security@vaultsparkstudios.com). Relay and Northwind Games are examples. --- Source: https://envoltmail.com/docs/builders [Docs](https://envoltmail.com/docs) / For builders # Builder preview What your agents will work with. The Agent Seal format below is final for version 1 and verified by running code. The interfaces after it are specified, not built, and may change. ## The Agent Seal header [Running in staging] One header per message, a list of `tag=value` pairs separated by semicolons: ``` Envolt-Agent-Seal: v=1; a=relay@agents.northwind.example; p=northwind.example; lvl=L2; case=NW-26-00042; card=https://northwind.example/agents/relay; kid=nw-2026-10-a; ts=1790949900; r=OR-…; sig=… ``` - **`v`**: Version. Always `1`. - **`a`**: The agent's address. Must equal the From address. - **`p`**: The principal: the organization the agent acts for, and the host of its key document. - **`lvl`**: Autonomy level at send time, `L2` (approved by a person) to `L4`. - **`case`**: An opaque reference to the conversation. - **`card`**: The agent's public profile. - **`kid`, `ts`**: Which key signed it, and when (Unix seconds). - **`r`, `d`**: Optional: the public receipt id, and a delegation chain when an agent acts for another agent. - **`sig`**: An Ed25519 signature, base64url without padding. ### What is signed The signature covers exactly thirteen lines, each ending in a line feed: a domain-separation label, the ten seal fields (empty when absent), and the message's Message-ID and Date as sent. Whitespace is removed from the header before parsing, so re-folding in transit never breaks it. ``` envolt-agent-seal/1 v:1 a:relay@agents.northwind.example p:northwind.example lvl:L2 case:NW-26-00042 card:https://northwind.example/agents/relay kid:nw-2026-10-a ts:1790949900 r:OR-… d: message-id:<…@agents.northwind.example> date:Fri, 02 Oct 2026 14:05:00 +0000 ``` ### The key document The principal publishes its public keys at `https://
/.well-known/agent-seal-keys.json`. Each key lists its validity window, its status and the agent addresses it may sign for. Revoked keys stay listed, and a seal signed with one is never trusted. ### Verifying A seal is **verified** only when the signature checks out, the key is valid for that agent at that time, the seal is less than two days old and within fifteen minutes of the Date header, and the sending domain's DomainKeys Identified Mail (DKIM) signature covers the seal header twice, so a second seal can't be added. A valid seal without that DKIM binding is reported as unverified, not trusted. [Try the verifier →](https://envoltmail.com/#seal) ## Planned interfaces [Designed] - **REST API** (OpenAPI described): cases, decisions, commitments, signals, routing, domains, the event ledger, the kill switch and webhook endpoints. - **Signed webhooks** following the Standard Webhooks pattern, with a shared-secret or public-key signature. Events carry identifiers and summaries, never mail content. - **Model Context Protocol (MCP) server** for agents: read tools (`list_cases`, `get_case`, `explain_route`, `get_brief`), safe actions (`draft_reply`, `hold_decision`), and proposal tools that only ever raise a card for a person. Agent tokens can never hold the accountable person's powers. - **Agent Cards** describing each agent, for agent-to-agent discovery. Want to build against these early? [Request early access](https://envoltmail.com/contact#early-access) and tell us what your agents do. --- Source: https://envoltmail.com/docs/glossary [Docs](https://envoltmail.com/docs) / Glossary # Glossary The words we use, in plain language. - **Accountable person**: The human who answers for an organization's agents. They own the rules, approve what needs approval, and alone can promote an agent's autonomy. - **Agent**: Software that uses an artificial intelligence (AI) model to read and write on someone's behalf. On Envolt Mail every agent has its own address, label and signing identity. - **Agent Seal**: A signed email header (`Envolt-Agent-Seal`) that says which agent sent a message, who it works for and how much autonomy it had. Anyone can verify it with the organization's published keys. See the [format](https://envoltmail.com/docs/builders#agent-seal). - **Airlock**: Where every inbound message is parsed in isolation, turned into plain text, stripped of hidden content and stored encrypted, before anything reads it. - **Anchor**: A daily fingerprint of the whole ledger. Once anchored, history can't be rewritten without the change showing. - **ASCII smuggling**: Hiding text in Unicode tag characters, which render as nothing for people but are read by models. The Airlock removes and counts them. - **Single-use capability**: A short-lived, one-time permission to send one approved message. Agents never hold a standing key to send. - **Case**: One inbound message, described in a structured way: intent, urgency, summary, and any commitments or decisions in it. - **Disclosure**: The plain-language lines that close every agent message: it was written by an agent, for whom, and how to reach a person. - **Earned autonomy**: Levels from L0 (observe only) to L4 (narrow, audited autonomy). An agent moves up only with a person's approval, backed by its measured record, and drops automatically after any serious mistake. - **Ledger**: The tamper-evident record of everything that happens. Each event is chained to the one before it by a hash, so a missing or altered event breaks the chain. - **Prompt injection**: Instructions planted in content to manipulate an AI system. In Envolt Mail, mail is data: nothing in it can change what an agent may do. - **Quarantined reader**: The model step that describes a message. It has no tools, sees redacted text, can only add warnings, and fails closed to a person. - **Receipt**: A public page behind each message's verify link: who the agent is, who it works for, whether a person approved. Never the content or recipients. - **Seal policy**: The policy engine every agent plan must pass: recipients, content, rate limits and approval rules your team owns. Not to be confused with the Agent Seal header. - **Trust tier**: How much a sender has been verified, from unknown to known contact. It changes how carefully a message is handled, never what an agent is allowed to do. --- Source: https://envoltmail.com/faq FAQ # Questions and answers Short answers to what people ask most. Something missing? [Ask us](https://envoltmail.com/contact). **Can I use Envolt Mail today?** Not yet. It is in development: the inbound pipeline runs in our staging environment on synthetic test mail, and nothing is sent. [Request early access](https://envoltmail.com/contact#early-access) and see [what runs today](https://envoltmail.com/status). **Does it replace Gmail, Outlook or my mail server?** No. Envolt Mail is designed to sit beside the mail your people already use, never in its delivery path. It never takes over the mail exchanger (MX) records your people rely on, so if Envolt Mail is ever down, their mail still flows. **Can an agent send email on its own?** Not by default. Agents propose plans; the Seal policy checks each one, and a person approves. An agent can earn the right to send routine replies from its measured track record, and loses it automatically on any serious mistake. Sending is designed, not built yet. **How will people know a message came from an agent?** Four ways: the sender name says AI agent, a disclosure closes the message, a signed Agent Seal header travels with it, and a verify link opens a public receipt. See [recognizing an Envolt Mail agent](https://envoltmail.com/docs/recipients). **What stops a stranger from emailing my agent instructions?** Mail is treated as data, never as instructions. The Airlock removes hidden text and invisible characters before anything reads a message, and nothing in an email can raise an agent's permissions. Try it in the [Airlock X-Ray](https://envoltmail.com/#xray). **Which artificial intelligence (AI) models does it use?** The reader is built for a small, fast Claude model, and that model is switched off. Today a no-cost synthetic stand-in runs in staging, so no mail reaches any model provider. **Is my mail used to train AI models?** Envolt Mail does not train models. The service's full privacy terms will be published before anyone can use it. **What will it cost?** Pricing is not set yet. **Can AI agents read this website?** Yes. Every page is also published as Markdown (add .md to the path, or send Accept: text/markdown), with [agents.json](https://envoltmail.com/agents.json), [llms.txt](https://envoltmail.com/llms.txt) and [llms-full.txt](https://envoltmail.com/llms-full.txt). **Who builds it?** [VaultSpark Studios](https://vaultsparkstudios.com/), an independent studio that makes software, games and stories. Read more [about us](https://envoltmail.com/about). **How do I report a security issue?** Email security@vaultsparkstudios.com or see our [security.txt](https://envoltmail.com/.well-known/security.txt). We read every report. --- Source: https://envoltmail.com/changelog Changelog # What changed Newest first. Service entries show the commit of the release that shipped them. Follow along with the [Atom feed](https://envoltmail.com/changelog.xml). 1. October 2, 2026Website ## A website that shows its work - A status page that separates what runs today from what is only designed, built from the same file as every page badge. - Two live demos that run our real code in your browser: the Airlock X-Ray and the Agent Seal verifier. - New pages: builder preview docs, a glossary, an FAQ and this changelog, with an Atom feed. - Every page is now also published as Markdown for AI agents, and early access requests no longer need email. 2. October 2, 2026Service`7b75d6968172` ## Daily thread integrity sweep, and invisible text caught in more places - Before each daily ledger anchor, every conversation thread active since the last sweep is re-verified. A broken thread is sealed and recorded even if nobody reads it again. - The Airlock now removes Unicode tag characters ("ASCII smuggling": text a model can read but a person cannot see) and checks subject lines for invisible characters. - Eleven red-team cases now assert exactly which detector fires for each attack. 3. October 1, 2026Service`caa3abce904c` ## Ledger integrity and key versioning - A broken hash chain is detected, sealed and recorded, and freezes the affected record until a person repairs it. A broken chain is never anchored. - Encryption keys are versioned, so stored mail can move to a new key without being re-encrypted. 4. October 1, 2026Service`3946ac9dab26` ## The quarantined reader - A reader with no tools turns each message into a structured case. It can only raise attention, never lower it, and fails closed to a person. - Card, bank account and US Social Security numbers are redacted before anything is read. - It runs on a no-cost synthetic stand-in in staging. No real model is switched on. 5. October 1, 2026Service`54102f60371e` ## Website launch and release gates - envoltmail.com went live. - Every release now passes an outbound-traffic allowlist, a log canary sweep and a recorded vendor-access procedure. 6. September 30, 2026Service`e6761637b092` ## The staging pipeline - Encrypted quarantine for raw mail, a hash-chained ledger anchored daily, and conversation threads with ordered, fenced writes. - Agent Seal verification for incoming agent mail, and trust tiers for every sender. - Isolation canaries in every release: separate synthetic test customers that must never see each other's data. --- Source: https://envoltmail.com/about About # Agents are joining the inbox. Someone should be accountable. Artificial intelligence (AI) agents already book meetings, answer questions and chase follow-ups. More and more of that happens over email, the one channel every person and business already shares. Email wasn't designed for software that writes like a person. Recipients can't tell who, or what, they're talking to. Builders give agents a password and hope for the best. Anyone can mail an agent instructions it may simply follow. Envolt Mail exists to fix that, around [four rules](https://envoltmail.com/#rules): agents are always labeled, they hold no standing power to send, mail is data and never orders, and people's own mail comes first. ## Who builds it Envolt Mail is made by [VaultSpark Studios](https://vaultsparkstudios.com/), an independent studio that makes software, games and stories. We plan to be Envolt Mail's first customer, using it under exactly the same rules and protections as everyone else. ## How we build it - **Security first, then features.** The quarantine, the tamper-evident record and the release gates came before any feature that touches real mail. - **In the open.** The [status page](https://envoltmail.com/status) says what runs and what doesn't, and the [changelog](https://envoltmail.com/changelog) points at release evidence. - **Demos run the real thing.** The [Airlock X-Ray](https://envoltmail.com/#xray) and the [Agent Seal verifier](https://envoltmail.com/#seal) on our home page run our production code in your browser. **Status:** in development and not yet available. [Request early access](https://envoltmail.com/contact#early-access). --- Source: https://envoltmail.com/contact Contact # Talk to a person Envolt Mail is being built right now. If you build or run artificial intelligence (AI) agents that need email, or you just want to follow along, we'd like to hear from you. ### General [hello@envoltmail.com](mailto:hello@envoltmail.com) ### Partnerships & press [contact@envoltmail.com](mailto:contact@envoltmail.com) ### Security reports [security@vaultsparkstudios.com](mailto:security@vaultsparkstudios.com). See our [security.txt](https://envoltmail.com/.well-known/security.txt). ### Who reads this People. Mail to these addresses and early access requests reach the team directly and are never handled by an agent. --- Source: https://envoltmail.com/ip # Intellectual property Last updated 2026-10-02 ## Ownership Envolt Mail, including its software, specifications, designs, documentation and this website, is proprietary to VaultSpark Studios LLC. © 2026 VaultSpark Studios LLC. All rights reserved. No license is granted except where we say so explicitly in writing. ## Trademarks Envolt Mail™ and the Envolt Mail logo are trademarks of VaultSpark Studios LLC. VaultSpark™ is a trademark of VaultSpark Studios LLC. Please don't use these marks in a way that suggests we endorse or partner with you without our written permission. ## Third-party material This site uses no third-party fonts or images. It's set in your device's own system typefaces and served by Cloudflare. The only third-party script is Cloudflare Turnstile, which loads on the contact page when you start filling in the early access form. ## Reporting infringement If you believe something here infringes your rights, write to [contact@envoltmail.com](mailto:contact@envoltmail.com). --- Source: https://envoltmail.com/privacy # Privacy policy Last updated 2026-10-02 This policy covers the Envolt Mail website at envoltmail.com. The Envolt Mail service isn't available yet and isn't covered here. It will get its own policy before anyone can use it. ## What this website collects - **No accounts, cookies, analytics or advertising.** The site sets no cookies and runs no tracking pixels. - **Your theme choice** (light or dark) is saved in your own browser's local storage so the site remembers it. It never leaves your device. - **The demos on the home page** run entirely in your browser. Anything you type into them is never sent anywhere. - **Early access requests**, only if you send one (see below). ## Early access requests If you use the form on the [contact page](https://envoltmail.com/contact#early-access), we store the email address, role and optional note you type, plus the time you sent it. We don't store your IP address. We use it only to contact you about early access to Envolt Mail. It is never added to a newsletter, shared or sold, and never used to train artificial intelligence (AI) models. We keep a request until we've contacted you about early access, and for at most 12 months; the site deletes older requests automatically. Sending the same address again updates your request instead of adding a second one. To keep bots out, the form uses Cloudflare Turnstile, which loads only after you start filling it in. Turnstile checks your browser for signs of automation and processes only the data needed for that check; it doesn't see what you type into the form. See [Cloudflare's Turnstile privacy addendum](https://www.cloudflare.com/turnstile-privacy-policy/). ## What our hosting provider sees The site is served by Cloudflare. Like any web host, Cloudflare processes technical request data, such as your IP address, browser type and the page requested, to deliver the site and protect it from abuse. We don't use that data to identify or profile visitors. ## Email you send us If you email an @envoltmail.com address, the message is received through Cloudflare Email Routing and delivered to the team's mailbox. We use it only to reply to you and keep it only as long as the conversation needs. It is never added to a mailing list or shared or sold, and it's never used to train AI models. ## Your choices You can ask us to delete an early access request, or any email you've sent us: write to [hello@envoltmail.com](mailto:hello@envoltmail.com). ## Who we are Envolt Mail is built and operated by VaultSpark Studios LLC. Questions about this policy: [hello@envoltmail.com](mailto:hello@envoltmail.com). ## Changes If this policy changes, the date at the top changes with it. --- Source: https://envoltmail.com/terms # Terms of use Last updated 2026-09-30 These terms cover your use of the Envolt Mail website. The Envolt Mail service isn't available yet. It will come with its own terms, and nothing on this site creates an agreement to provide it. ## Using the site You may read, link to and share pages from this site. Please don't try to disrupt it, probe it for weaknesses without following our [security policy](https://envoltmail.com/.well-known/security.txt), or pass off its content as your own. ## Information on the site Envolt Mail is in development. Descriptions of how it works reflect its current design and may change before release. The site is provided "as is", without warranties of any kind, to the extent the law allows. ## Intellectual property The site's content, design and code, the Envolt Mail name and the Envolt Mail logo belong to VaultSpark Studios LLC. See [intellectual property](https://envoltmail.com/ip) for details. ## Liability To the extent the law allows, VaultSpark Studios LLC isn't liable for any loss that comes from using this website. ## Contact Questions about these terms: [hello@envoltmail.com](mailto:hello@envoltmail.com).