Trust center

Built to keep your mail yours

An agent with email access is a powerful thing to hand to software. Envolt Mail is designed so that power stays bounded, visible and accountable. This page lists every control, says whether it runs today, and links to how it works.

Running in staging Built and running on our staging environment, on synthetic test mail only. Designed Specified in detail, not built or not switched on yet. What runs today →

The controls

Mail can't command an agent Running in staging
Prompt injection plants instructions in an email to steer an agent. Here, message content is always data: what a person can't see is stripped before anything reads it, detectors flag instruction-like text, and the reader has no tools and can't lower a warning. How the Airlock works · try to beat it.
Encrypted per message Running in staging
Raw mail and attachments are encrypted with a unique key per message. Those keys are wrapped under a key specific to each customer and bound to where the data is stored, so a copied file is unreadable anywhere else. Keys are versioned, so they can be rotated without re-encrypting mail.
Customers can't see each other Running in staging
Each organization will get its own encrypted storage, keys and records. Every release is already checked for this with isolation canaries: planted markers that one synthetic test customer must never be able to find in another's data.
A tamper-evident record Running in staging
Every event goes on a chained record, and a broken chain freezes the affected record until a person repairs it. How the ledger works · tamper with one.
No standing send rights Designed
Agents will never hold credentials to send mail. Each approved message will get a single-use capability that expires quickly and can't be replayed. A kill switch will halt every agent, or a single one, instantly.
Staff can't read your mail Designed
Staff will have no standing access to anyone's mail content, including our own studio's. Support access will happen only with your approval, time-boxed and recorded where you can see it.
Your mail path stays yours Designed
Connections will be read-only and sit beside your existing mail. Envolt Mail never takes over the mail exchanger (MX) records your people rely on, so if it's ever down, their mail still flows.
Our domains, done properly Live
envoltmail.com publishes Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) records and is signed with Domain Name System Security Extensions (DNSSEC). Agent mail will be authenticated the same way.

Every release passes the gates

A release can't ship unless the full test suite passes, including a red-team corpus of hostile emails, and the bundle is scanned for anything that shouldn't leave the building. Outbound traffic is limited to an allowlist, and logs are swept for planted canaries. Each release leaves a receipt. See the latest →

Who handles data

ProviderWhat forToday
CloudflareHosting for this website and the service, encrypted storage, routing mail sent to our own addresses, and the bot check on the early access form.Live
ZohoThe team's own mailbox, where mail sent to our addresses is delivered and answered by people.Live
AnthropicThe model behind the quarantined reader. It would receive redacted text only, never attachments or credentials.Switched off

No mailbox is connected and no mail reaches any model today. We'll update this table before that changes.

How long data is kept

Reporting a vulnerability

Report a vulnerability to security@vaultsparkstudios.com. Our disclosure policy says what to expect.

We read every report. Our security.txt has the machine-readable version.

Thanks

No reports yet. People whose reports lead to a fix are credited here, with their permission.