Built for real businesses handling real money.
Last updated 28 July 2026
EmailCos combines strong encryption, zero retention, deterministic guards, and mandatory human approval for high-risk actions.
AES-256-GCM at rest
Every token, message body, and analysis result encrypted with rotated keys.
OAuth2 & app-passwords
Native OAuth for Gmail, Outlook, Yahoo. Encrypted app-passwords for the other 24 providers.
Zero data retention
Analysis is ephemeral. We do not train on your mail. Revoke access at any time.
SOC 2, GDPR, POPIA ready
Auditable access logs, EU/UK/ZA data residency options, and DPA on request.
Deterministic Validator — Banking Firewall
The LLM extracts amounts and intent, but the validator is pure code. It checks math sanity, historical variance, and extra-zero errors. If a value exceeds your historical baseline by more than 50%, the system escalates to L3 HIGH RISK and blocks automatic execution.
- Math sanity check: totals must equal stated sums
- Historical variance: >50% deviation triggers escalation
- Extra-zero check: catches R15,000 vs R150,000 style mistakes
Human-in-the-Loop
EmailCos never transacts. Any action over R500, or any action flagged as high-risk, requires your explicit approval. The system is read/draft-only by design.
Zero retention
Analysis is ephemeral. Email bodies are processed in RAM and purged within 60 seconds. Metadata is retained for 30 days for reporting and then deleted. We do not train models on your data.
Compliance readiness
EmailCos is architected for SOC 2, GDPR, and POPIA. We offer EU/UK/ZA data residency options, auditable access logs, and a DPA on request for Business plans.
Platform controls
Authentication, encryption, tenancy, and logging are enforced at the platform layer, independent of the model.
- OAuth2 for Gmail, Outlook 365, Yahoo and Zoho; short-lived JWT session tokens for the app itself
- AES-256-GCM encryption at rest for tokens, app passwords, and derived metadata, with rotated keys
- TLS 1.3 for all transport between your browser, our edge, and provider APIs
- Multi-tenant isolation via row-level security — every query is scoped to the authenticated account
- Audit logging of every action, approval, and access event with tamper-evident SHA-256 hash chaining
- One-click revocation: OAuth tokens revoked and encrypted app-password vault entries purged
These controls are aligned to SOC 2, GDPR, and POPIA principles. Alignment is not certification — we do not claim a completed SOC 2 audit report, and we will say so plainly in any security review.
Deterministic Validator — Code-Based Risk Checks
When an email mentions an unusually large financial amount, deterministic code — not the AI model — flags it for human review before any suggested reply is used. The validator runs a math sanity check, compares amounts against your typical email history, and catches extra-digit errors. It analyses email content only.
Human-in-the-Loop — You Stay in Control
EmailCos reads email content and drafts suggested replies — it never initiates payments or takes financial action on your behalf. Flagged emails always wait for your explicit approval. SARS / tax notices automatically disable archiving. Every action is recorded in a tamper-evident SHA-256 audit trail.
POPIA 7441 Zero-Retention Proof
Primary region jnb (Johannesburg). Information Officer Xoli Dlabantu. No volumes in fly.toml = RAM only. auto_stop_machines wipes RAM. 0 days email body · 30 days metadata · 60s analysis purge. EU / UK / ZA residency.