What we protect, how, and what we do not claim.
Support mailboxes contain some of the most sensitive material a company holds. This page describes the controls that exist today, in plain language.
Eight controls that are in place today.
Data separation between companies
Every record carries the workspace it belongs to, and access is enforced by row-level security in the database — not only by the application. A query made on behalf of one company cannot return another company's rows.
Permission-based access
What a person can read and do follows the role they hold in the workspace. Connecting or disconnecting a mailbox and managing knowledge are restricted to owners and administrators.
Secure authentication
Sign-in uses email and password or your Google account, handled by our authentication provider. Sessions are scoped to the workspaces you are a member of.
Explicit, revocable mailbox access
Signing in to QlintAI does not grant access to any mailbox. Mailbox permission is a separate, deliberate grant, made per mailbox, and it can be withdrawn at any time — after which QlintAI stops reading it.
Human control over outbound email
QlintAI does not send external email on its own. Approval is an action taken by a named person, and high-risk cases are routed to a human rather than resolved automatically.
Knowledge boundaries
Company knowledge is used only to answer for the company that provided it. Your documents and conversations are not used to answer for another customer.
Untrusted content, treated as such
Incoming email is data, never instructions. Text inside a customer message cannot change what QlintAI is allowed to do.
Minimised logging
Audit records describe what happened and who did it. They do not contain message bodies, recipient data, access tokens or signed URLs.
What we are not claiming.
A security page is only useful if you can trust the parts that sound impressive. So here is the other half.
QlintAI does not hold SOC 2, ISO 27001 or any other third-party security certification today. When that changes, it will be stated here with the report date.
We are a young company. Our controls are real, but they have not yet been audited by an external party.
AI reasoning runs on OpenAI models, which means the content required to answer a case is processed by that provider under our agreement with them.
If a control you need does not exist yet, ask. We would rather lose a deal than describe something we have not built.
Reviewing us properly?
Send your security questionnaire and we will answer it as it stands today, including the questions where the answer is “not yet”. For data handling in detail, see the privacy policy.