Security & data handling
No badge wall, no vague reassurances — the specific controls, in plain English, all checkable against our public Privacy Policy and sub-processor list before you sign up.
Draft-only is the default, not a mode: every reply waits in an approval queue. Full-auto is an explicit opt-in, per mailbox, when the queue has earned it. Even in full-auto, your escalation rules hold sensitive threads for a person, and on Pro and above the customer-mood read holds heated ones too; and every reply the agent sends by itself carries an AI disclosure (EU AI Act, Article 50). Replies you approve are your own communication.
Sign-in and mailbox access go through Microsoft's or Google's own consent screens, scoped to least privilege: read mail, send the replies you approve, calendar events if you enable Scheduling. Tokens are encrypted at rest. You can revoke access from your side at any time, and disconnecting a mailbox deletes its tokens and stops all processing.
Isolation is enforced in the database itself with row-level security — your mail, rules, knowledge, bookings and invoices are strictly separated from every other customer's. Data is encrypted in transit, production access is restricted and audited, and every agent action lands in an audit log.
Database in the UK (London — Supabase, eu-west-2). Application in the EU (Frankfurt — Render). AI drafting by Anthropic in the US, receiving your email content as the prompt under UK data-transfer safeguards (IDTA / Standard Contractual Clauses); retrieval embeddings by Voyage AI (US) and the assistant's voice by OpenAI (US), under the same safeguards. Card details go straight to Stripe and never touch our systems (how BLAM8 uses Stripe). The full sub-processor list is public in the Privacy Policy.
We don't use your content to train AI models and we don't sell personal data; Anthropic, Voyage and OpenAI don't train on API data either. Google-connected mailboxes are handled under Google's Limited Use policy — no ads, no humans reading your mail outside the narrow cases the policy allows. Your data is used to run your service, full stop.
Handled email content (the incoming message, the draft and the notes made from them) is automatically redacted after 90 days, keeping only the audit record. Knowledge sources stay until you delete them. Your operational records export as CSV/Excel any time, and a verified deletion request to hello@blam8.com removes the lot.
The honest position on certifications: BLAM8 is a young product and doesn't yet hold SOC 2 or ISO 27001. What we offer instead is specifics — what's stored, where, who touches it, and the controls above — published where you can check them before you ever connect a mailbox. Data handling is built around UK GDPR; only strictly-necessary cookies, no trackers.
We don't claim "no hallucinations" — nobody honestly can. The safety story is structural: replies are grounded in your own uploaded knowledge and the agent says "I don't know" rather than invent; a human approves everything until you switch full-auto on; escalation rules and the mood read pull the risky conversations back to a person; and any wrong line becomes a standing never-rule in one click. Grounding, approval, escalation, correction.
Security questionnaires, data-processing questions, or a control you need that isn't listed — email hello@blam8.com and you'll get a straight answer. For the legal detail: the Privacy Policy covers roles, lawful bases, retention and your UK GDPR rights, and the Terms of Service cover the contract.
Free 14-day pilot, no card — nothing sends without a human until you decide it should.
BLAM8 assistant