Trust & governance

Safety is the architecture, not a setting.

Every displayed pathway can show why it exists, what supports it, how current it is and who decided.

The controls that qualify a route before anyone sees it.

01

Data minimisation

Raw mail bodies, attachments, passwords and unrestricted contact lists are excluded by default; approved metadata and field allow-lists are used.

02

Tenant protection

Organisation Workspace data, configuration, queues, audit events and keys remain tenant-bound with forced database row-level isolation.

03

Evidence and provenance

Every displayed pathway can show why it is present, what evidence supports it, how current it is, the source policy and its review state.

04

Human control

No automatic message, introduction, merge or sensitive approval. Relationship owners and administrators decide.

05

External review

External candidates remain staged until an authorised reviewer accepts, rejects, defers or approves a controlled merge.

06

AI controls

AI assistance is constrained by approved use cases, redaction, model profiles, prompt and schema versioning, output validation, monitoring, kill-switches and human oversight.

07

Auditability

Connector actions, reviewer decisions, route actions, exports and policy changes create auditable records.