Skip to content

The honest version, badges and all

Is AI Email Safe?

Letting software read your inbox is a real trust decision, and it deserves a real answer. Here is where your data goes, what protects it, what the law asks of you — and what we do not claim.

The Honest Answer: It Depends on Three Things

“Is AI email safe?” is the right question, and it has a real answer rather than a reassuring one.

Letting an AI handle your inbox means the contents of that inbox — client details, commercial terms, sometimes health or financial information — pass through the system that reads and drafts. That is not a reason to avoid it; it is a reason to ask exactly the questions you would ask before handing those emails to any third party. Whether it is safe comes down to three things: where your data goes, who can reach it, and whether a human stays in control of what gets sent.

On the first, our answer is Australian data centres — processing and storage onshore, so the correspondence does not leave the country to be read. On the second, encryption in transit and at rest, access controls, and an audit trail of what the system did. On the third, a human-in-the-loop model where the AI drafts and a person approves, so nothing goes out in your name unless you decided it should.

We will also tell you what we are not. We are a small independent Australian business, and we do not hold SOC 2 or ISO 27001 certification. If your procurement demands a certified provider, choose one — we would rather say so here than after you sign. What we offer instead is genuine transparency: we put the architecture and the data handling in writing, and we answer the awkward questions directly, including the one most vendors dodge.

What Actually Protects Your Email

The controls that matter, stated as what they are rather than dressed up as more than they are.

Australian Data Residency

Processing and storage in Australian data centres. Your inbox is not shipped offshore to be read, which keeps you on the right side of the questions a client or auditor will ask.

  • Processing and storage onshore, in Australia
  • No offshore round-trip to read your email
  • Documented in writing for sign-off
  • Matters most for regulated and confidential work

Encryption In Transit & At Rest

Email is encrypted while it moves and while it is stored, so intercepted or accessed data is unreadable without the keys. Standard practice, done properly.

  • Encrypted connections for data in transit
  • Encryption at rest for stored data
  • Secure OAuth — we never see your password
  • Keys managed, not left lying in config

Human-in-the-Loop by Default

The AI drafts; a person approves. Nothing sends in your name unless you configured that category to auto-send. This is the control that makes AI email safe to trust.

  • Draft-first mode with one-click approval
  • Auto-send only where you deliberately enable it
  • Recommended default for sensitive correspondence
  • You stay accountable for what leaves the building

Your Data Trains Nothing Else

Your email serves your assistant and no one else. It is not pooled with other customers or used to train models for other businesses. Your correspondence stays yours.

  • Not used to train models for other customers
  • Not pooled with other businesses’ data
  • Used only to run your inbox
  • A question worth asking every vendor

Access Controls & Audit Trail

Access to your data is controlled and logged. You can see what the system did — what it read, categorised, drafted and sent — rather than trusting a black box.

  • Role-based access to your data
  • Audit trail of processing and sends
  • Visibility into what the AI did and when
  • Supports your own compliance record-keeping

Privacy Act 1988 Alignment

Built around the Australian Privacy Act 1988 and the Australian Privacy Principles — including the offshore-disclosure obligation under APP 8 that a lot of AI email marketing quietly skips.

  • Handling aligned to the APPs
  • APP 8 offshore-disclosure position stated in writing
  • Retention configured to your obligations
  • General information, not legal advice

What We Do Not Claim

A security page is more trustworthy for what it refuses to overstate. So here is the honest ledger.

What we do provide

  • Processing and storage in Australian data centres
  • Encryption in transit and at rest
  • Human-in-the-loop approval before sending
  • Access controls and an audit trail
  • Handling aligned to the Privacy Act 1988 and APPs
  • The data architecture, documented in writing

What we do not claim

  • We do not hold SOC 2 certification
  • We do not hold ISO 27001 certification
  • We are not IRAP-assessed
  • We do not process data classified PROTECTED or above
  • We do not promise a specific uptime SLA figure here
  • We will point you elsewhere if your rules require the above

If your procurement hard-requires a certification we do not hold, choose a provider who has it — we would rather tell you that in the first conversation than win work we should not. Where those certifications are not mandated, the controls above are what genuinely protect your email, and we will show you exactly how they work.

Three Questions to Ask Any AI Email Vendor

Use these on us, and on everyone else you shortlist. A straight answer is itself a signal.

1

Where does my email actually go?

Ask whether processing and storage are onshore, and specifically whether your email is disclosed to an overseas model provider. Under APP 8 that is your accountability. If the answer is vague or the offshore step is glossed over, treat that as the answer.

2

What certifications do you hold — really?

Ask directly, and watch for badges implied rather than held. A vendor willing to say plainly what it does not hold is usually more trustworthy than one displaying logos it cannot substantiate. Ours: Australian data residency and documented handling, not SOC 2 or ISO 27001.

3

Can it send without a human, and is my data training your models?

Confirm you control what auto-sends, and confirm your correspondence is not used to train models for other customers. The safe default is human-in-the-loop and no cross-customer training — anything looser should be a deliberate, informed choice, not a surprise in the terms.

Read Further

How AI Inbox Triage Works

The mechanism behind the reading and sorting — and how triage stays a sorting tool, never a deciding one.

Learn more

AI Email for Healthcare

The industry where the data question is sharpest — how patient email is handled under the Privacy Act with health information in play.

Learn more

Our Privacy Policy

The formal detail on how we collect, use, store and protect your information — the document behind the plain-English answers here.

Read the policy

Frequently Asked Questions

The data, privacy and security questions businesses ask before letting an AI touch the inbox.

Ask the Awkward Questions. We Will Answer Them.

Bring your privacy and security requirements to the free consultation and you will get the architecture in writing — including a straight answer on whether we fit your obligations, or whether you need a certified provider instead.

Prefer to talk it through first? Call (03) 9999 7402 or send us a message.