SECURITY
How DuoInbox bounds what the agent can reach
This page describes how the product behaves. It does not claim a certification, an attestation, or a security guarantee, because DuoInbox holds none. The questions a security review normally asks that DuoInbox cannot answer yet are listed at the bottom of this page rather than left off it.
THE ACCESS MODEL
The agent never holds the mailbox
Hermes, the agent that does the work, holds no Gmail credentials. It cannot open the mailbox, search it, or act on it on its own initiative.
DuoInbox sits between the mailbox and the agent. It watches incoming Gmail, evaluates the workflow rules you define, and starts a run only on a message a rule matches. Mail that matches nothing stays ordinary inbox work and never reaches the agent.
When a rule does match, DuoInbox mediates governed MCP access for that one run. The run receives the matched thread and the actions the workflow permits. It does not receive the mailbox.
MCP gives an agent email tools. DuoInbox decides which message wakes it, which workflow applies, and what that workflow permits. The permission level belongs to the workflow, not to the agent: a workflow is set to summarize only, prepare a proposed reply, or send after human approval, and a run cannot act above the level of the workflow that started it.
BEFORE ANYTHING LEAVES
What stops before anything leaves
Sending is the consequential step, so the controls sit in front of it rather than in a policy document.
- 01 Approval before external send
- External send is blocked until a person approves the version that goes out. The review queue shows the source message, the proposed reply, the recipients, and the policy checks together, so approving is a decision rather than a confirmation.
- 02 Recipient restrictions
- Who a reply may go to is set on the workflow. An added or changed recipient is checked as a policy event in its own right, not read as incidental text inside the reply.
- 03 Sending limits
- Each workflow carries a ceiling on approved outbound actions. A workflow that starts behaving in a way you did not expect reaches its ceiling instead of continuing.
- 04 Immediate kill switch
- One visible runtime control stops new runs. It sits beside the workflow permissions and the audit activity in the control view, so stopping the agent is an operator action rather than a support request.
What these controls do not stop
- They do not review the approver. The queue puts the recipients, the matched rule, and the checks in front of a person, and that person still makes the call. An approved reply sends.
- They do not apply to mail that matched no workflow. That mail stays ordinary inbox work for your team, and DuoInbox does not stand between people and their own replies.
- They do not replace Google Workspace administration. Access for the people on your team is still granted, and revoked, in Google Workspace.
THE AUDIT CHAIN
What is recorded
One run produces one chain, recorded in order.
- The mailbox event that arrived.
- The workflow rule it matched.
- The actions the agent took inside that run.
- The policy checks that were applied.
- The human decision: approved, changes requested, or rejected.
What an operator can reconstruct from it
- Why a run started on a particular message, and which rule was responsible.
- What that run was permitted to do at the moment it ran.
- Which recipients an approved reply went to, and who approved it.
- Whether a repeated action was a retry of the same event or a new request, because event identity stays stable across retries.
The chain is a record of what the system did. It is not a retention policy. How long those records are kept is not published, and that question is answered among the open questions below rather than implied here.
THIS WEBSITE
What this website collects
This site is not connected to any mailbox. Requesting early access grants DuoInbox no access to your Gmail, creates no account, and connects nothing.
The early-access form asks for a work email and, optionally, one line about the inbox workflow you would govern first. Those two fields are what the form sends. They are stored so a person can read the request and reply to you at that address. The form also carries a field that stays empty for anyone using the page normally; a submission that fills it is treated as automated and is not stored.
A written question through the contact page works the same way: an address to reply to, and what you want to ask. DuoInbox does not publish a response-time commitment, so this page does not offer one.
Those website records are kept for 24 months from the last contact and are then deleted. A verified request to have one deleted sooner is actioned within 30 days. This applies to the website only, not to mail inside a customer's Google Workspace.
NOT PUBLISHED YET
Security questions we cannot answer yet
A security review asks questions this page cannot answer today. Leaving them off would make the disclosure look more complete than it is. Here they are, with what is true now. Each one is a decision we have not published, not a part of the product that is missing.
- Does DuoInbox hold SOC 2, ISO 27001, or any other certification?
- No. DuoInbox does not hold one and does not claim one, and no formal attestation has been performed. If your review requires a certification, say so in your message and you will get a direct answer about where that stands rather than a badge on this page.
- Where is product data stored, and for how long?
- Not published. We would rather leave this blank than publish a location and a retention period that then change. Ask and you will be told what is settled and what is not. This is a separate question from the website: what the forms on duoinbox.com collect, and how long those records are kept, is set out in full on the privacy page.
- How is data encrypted?
- Not published. DuoInbox has not published an encryption implementation, so treat any specific claim about one attributed to DuoInbox as not coming from us.
- What is the deployment model?
- Not published. Whether DuoInbox runs as a hosted service, inside your own infrastructure, or both is a decision we have not published, and nothing on this site should be read as implying one.
- Which identity providers are supported?
- Not published. The initial scope is a Google Workspace mailbox, which is a statement about where the mail lives rather than about the sign-in and directory options DuoInbox will support.
- How does the Slack integration behave?
- Slack notifications are part of the control set. The behavioral detail — which events notify, where they post, and what can be acted on from Slack — is not published.
SECURITY REVIEW
Send us the questions this page does not answer
Write down what your review needs and send it. You will get a direct answer, including “not decided yet” where that is the honest one, and you will not be sent a badge instead of a reply.