Security & data handling
No badge wall, no vague reassurances — the specific controls, in plain English, all checkable against our public Privacy Policy and sub-processor list before you sign up.
Draft-only is the default, not a mode: every reply waits in an approval queue. Full-auto is an explicit opt-in, per mailbox, when the queue has earned it. Even in full-auto, your escalation rules and the customer-mood read hold sensitive and heated threads for a person, and every reply the agent sends by itself carries an AI disclosure (EU AI Act, Article 50). Replies you approve are your own communication.
Sign-in and mailbox access go through Microsoft's or Google's own consent screens, scoped to least privilege: read mail, send the replies you approve, calendar events if you enable Scheduling. Tokens are encrypted at rest. You can revoke access from your side at any time, and disconnecting a mailbox deletes its tokens and stops all processing.
Isolation is enforced in the database itself with row-level security — your mail, rules, knowledge, bookings and invoices are strictly separated from every other customer's. Data is encrypted in transit, production access is restricted and audited, and every agent action lands in an audit log.
Database in the UK (London — Supabase, eu-west-2). Application in the EU (Frankfurt — Render). AI drafting by Anthropic in the US, receiving your email content as the prompt under UK data-transfer safeguards (IDTA / Standard Contractual Clauses); retrieval embeddings by Voyage AI (US) under the same safeguards. Card details go straight to Stripe and never touch our systems. The full sub-processor list is public in the Privacy Policy.
We don't use your content to train AI models and we don't sell personal data; Anthropic and Voyage don't train on API data either. Google-connected mailboxes are handled under Google's Limited Use policy — no ads, no humans reading your mail outside the narrow cases the policy allows. Your data is used to run your service, full stop.
Handled email content (the incoming message and the draft) is automatically redacted after 90 days, keeping only the audit record. Knowledge sources stay until you delete them. Your operational records export as CSV/Excel any time, and a verified deletion request to hello@blam8.com removes the lot.
The honest position on certifications: BLAM8 is a young product and doesn't yet hold SOC 2 or ISO 27001. What we offer instead is specifics — what's stored, where, who touches it, and the controls above — published where you can check them before you ever connect a mailbox. Data handling is built around UK GDPR; only strictly-necessary cookies, no trackers.
We don't claim "no hallucinations" — nobody honestly can. The safety story is structural: replies are grounded in your own uploaded knowledge and the agent says "I don't know" rather than invent; a human approves everything until you switch full-auto on; escalation rules and the mood read pull the risky conversations back to a person; and any wrong line becomes a standing never-rule in one click. Grounding, approval, escalation, correction.
Security questionnaires, data-processing questions, or a control you need that isn't listed — email hello@blam8.com and you'll get a straight answer. For the legal detail: the Privacy Policy covers roles, lawful bases, retention and your UK GDPR rights, and the Terms of Service cover the contract.
Free 14-day pilot, no card — nothing sends without a human until you decide it should.
BLAM8 assistant
Ask about plans, modules or setup