Security

An agent acting on your behalf
has to ask first.

Giving something that decides on its own access to your store, your inbox and your CRM is a serious decision. Here is what we built so it stays reversible, visible and bounded.

The four controls

It is not trust. It is four concrete brakes.

  • You approve what matters

    Every agent has an approval policy. By default any destructive action stops and waits for your sign-off. You can raise it to “everything goes through me” or lower it to “just run”.

  • It cannot run away

    Every run has a cap on steps and on tool calls. An agent that loops stops itself, not when somebody notices.

  • You see everything it did

    Every tool an agent runs is recorded: which one, with what input, when, and with what result. Also who triggered it, even when that was a schedule.

  • Your company stands alone

    Every database query is scoped to your organization at the database level, not in application code. A bug in a query cannot hand you another company's data.

Access

Who gets in, and what they can do.

  • Second factor with an authenticator app, optional per user
  • Organization roles: owner, admin and member
  • Extended permissions for billing, editing and read-only
  • Every invitation and every role change is recorded
Your data

Where what you give us actually lives.

  • We do not hold your credentials

    Tokens for your connected apps and AI provider keys live encrypted in a secrets vault, not in a text column.

  • You own it

    Your end customers' personal data is processed strictly on your instructions. We do not sell it or share it with third parties.

  • Your content does not train models

    The providers we use operate under zero-retention, zero-training agreements on your data.

  • You can leave

    Export your documents, sheets, contacts and agents whenever you want. Disconnect an app and we revoke its access in under a minute.

What we do not have yet

The gaps, stated here and not in a meeting.

A security page that only lists strengths is useless for evaluating us. Here is what is missing today.

  • No SOC 2 or ISO 27001 certification

    We are not certified. We apply the practices, but there is no external audit backing that up, and we are not going to claim there is.

  • SSO/SAML is implemented, not switched on

    There is no button. On Enterprise it is configured with our team during onboarding.

  • Remote images in the webmail

    Our content policy allows loading images from any origin, because the webmail renders mail from any sender. Closing it needs an image proxy, and that is pending.

Still have questions?

Ask us whatever your security team needs.

If you are evaluating Napsix for a company with formal requirements, let's talk before you sign anything.

XIA
public