Built to keep your mail yours
An agent with email access is a powerful thing to hand to software. Envolt Mail is designed so that power stays bounded, visible and accountable. This page lists every control, says whether it runs today, and links to how it works.
Running in staging Built and running on our staging environment, on synthetic test mail only. Designed Specified in detail, not built or not switched on yet. What runs today →
The controls
- Mail can't command an agent Running in staging
- Prompt injection plants instructions in an email to steer an agent. Here, message content is always data: what a person can't see is stripped before anything reads it, detectors flag instruction-like text, and the reader has no tools and can't lower a warning. How the Airlock works · try to beat it.
- Encrypted per message Running in staging
- Raw mail and attachments are encrypted with a unique key per message. Those keys are wrapped under a key specific to each customer and bound to where the data is stored, so a copied file is unreadable anywhere else. Keys are versioned, so they can be rotated without re-encrypting mail.
- Customers can't see each other Running in staging
- Each organization will get its own encrypted storage, keys and records. Every release is already checked for this with isolation canaries: planted markers that one synthetic test customer must never be able to find in another's data.
- A tamper-evident record Running in staging
- Every event goes on a chained record, and a broken chain freezes the affected record until a person repairs it. How the ledger works · tamper with one.
- No standing send rights Designed
- Agents will never hold credentials to send mail. Each approved message will get a single-use capability that expires quickly and can't be replayed. A kill switch will halt every agent, or a single one, instantly.
- Staff can't read your mail Designed
- Staff will have no standing access to anyone's mail content, including our own studio's. Support access will happen only with your approval, time-boxed and recorded where you can see it.
- Your mail path stays yours Designed
- Connections will be read-only and sit beside your existing mail. Envolt Mail never takes over the mail exchanger (MX) records your people rely on, so if it's ever down, their mail still flows.
- Our domains, done properly Live
- envoltmail.com publishes Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) records and is signed with Domain Name System Security Extensions (DNSSEC). Agent mail will be authenticated the same way.
Every release passes the gates
A release can't ship unless the full test suite passes, including a red-team corpus of hostile emails, and the bundle is scanned for anything that shouldn't leave the building. Outbound traffic is limited to an allowlist, and logs are swept for planted canaries. Each release leaves a receipt. See the latest →
Who handles data
| Provider | What for | Today |
|---|---|---|
| Cloudflare | Hosting for this website and the service, encrypted storage, routing mail sent to our own addresses, and the bot check on the early access form. | Live |
| Zoho | The team's own mailbox, where mail sent to our addresses is delivered and answered by people. | Live |
| Anthropic | The model behind the quarantined reader. It would receive redacted text only, never attachments or credentials. | Switched off |
No mailbox is connected and no mail reaches any model today. We'll update this table before that changes.
How long data is kept
- Early access requests: until we've contacted you, and at most 12 months. Details.
- Mail, once connections exist: each customer will choose retention within limits, and every deletion will be recorded on the ledger. The default windows are still under legal review.
- This website: no cookies and no analytics. Cloudflare keeps short-lived technical request logs to run and protect it.
Reporting a vulnerability
Report a vulnerability to security@vaultsparkstudios.com. Our disclosure policy says what to expect.
- In scope: envoltmail.com, staging.envoltmail.com, and anything you can make the Lab demos do that they shouldn't, such as hidden text that survives the Airlock or a seal that verifies when it shouldn't.
- Please don't: access data that isn't yours, degrade the service for others, or send automated traffic to the early access form.
- What you'll get: a reply from a person, and, if you'd like, credit below once it's fixed.
We read every report. Our security.txt has the machine-readable version.
Thanks
No reports yet. People whose reports lead to a fix are credited here, with their permission.