BLAM8

Security & data handling

You're giving an AI your inbox. Here's exactly what happens to it.

No badge wall, no vague reassurances — the specific controls, in plain English, all checkable against our public Privacy Policy and sub-processor list before you sign up.

The controls that matter

A human approves every send — until you say otherwise

Draft-only is the default, not a mode: every reply waits in an approval queue. Full-auto is an explicit opt-in, per mailbox, when the queue has earned it. Even in full-auto, your escalation rules and the customer-mood read hold sensitive and heated threads for a person, and every reply the agent sends by itself carries an AI disclosure (EU AI Act, Article 50). Replies you approve are your own communication.

OAuth consent, never your password

Sign-in and mailbox access go through Microsoft's or Google's own consent screens, scoped to least privilege: read mail, send the replies you approve, calendar events if you enable Scheduling. Tokens are encrypted at rest. You can revoke access from your side at any time, and disconnecting a mailbox deletes its tokens and stops all processing.

One isolated tenant per company

Isolation is enforced in the database itself with row-level security — your mail, rules, knowledge, bookings and invoices are strictly separated from every other customer's. Data is encrypted in transit, production access is restricted and audited, and every agent action lands in an audit log.

Where your data lives — precisely

Database in the UK (London — Supabase, eu-west-2). Application in the EU (Frankfurt — Render). AI drafting by Anthropic in the US, receiving your email content as the prompt under UK data-transfer safeguards (IDTA / Standard Contractual Clauses); retrieval embeddings by Voyage AI (US) under the same safeguards. Card details go straight to Stripe and never touch our systems. The full sub-processor list is public in the Privacy Policy.

Your content is not training data

We don't use your content to train AI models and we don't sell personal data; Anthropic and Voyage don't train on API data either. Google-connected mailboxes are handled under Google's Limited Use policy — no ads, no humans reading your mail outside the narrow cases the policy allows. Your data is used to run your service, full stop.

Retention with a short fuse — and no lock-in

Handled email content (the incoming message and the draft) is automatically redacted after 90 days, keeping only the audit record. Knowledge sources stay until you delete them. Your operational records export as CSV/Excel any time, and a verified deletion request to hello@blam8.com removes the lot.

The honest position on certifications: BLAM8 is a young product and doesn't yet hold SOC 2 or ISO 27001. What we offer instead is specifics — what's stored, where, who touches it, and the controls above — published where you can check them before you ever connect a mailbox. Data handling is built around UK GDPR; only strictly-necessary cookies, no trackers.

Why an AI answering email is safe here

We don't claim "no hallucinations" — nobody honestly can. The safety story is structural: replies are grounded in your own uploaded knowledge and the agent says "I don't know" rather than invent; a human approves everything until you switch full-auto on; escalation rules and the mood read pull the risky conversations back to a person; and any wrong line becomes a standing never-rule in one click. Grounding, approval, escalation, correction.

Questions, or something we've missed?

Security questionnaires, data-processing questions, or a control you need that isn't listed — email hello@blam8.com and you'll get a straight answer. For the legal detail: the Privacy Policy covers roles, lawful bases, retention and your UK GDPR rights, and the Terms of Service cover the contract.

Check everything first. Then try it draft-only.

Free 14-day pilot, no card — nothing sends without a human until you decide it should.