Trust model

Access should be powerful. Permission should be narrow.

Reading and sending are separate capabilities. MailBridge exposes send/reply only after explicit mail.send authorization; delete, move and archive remain unavailable.

Separate read and send scopes

mail.read permits mailbox reading. mail.send is a separate explicit permission for send/reply. Destructive mailbox actions are not exposed in the preview.

Encrypted mailbox credentials

Stored mailbox credentials are encrypted at rest with AES-256-GCM and are not returned through the product UI or AI tools.

Account isolation

Mailbox ownership is scoped to the authenticated MailBridge account. A mailbox identifier alone is not sufficient to cross account boundaries.

Your mailbox stays upstream

Connecting or disconnecting MailBridge does not migrate or delete the upstream mailbox. The product is an access bridge, not the mailbox host.

Message content is fetched on demand

The current application database stores connection and account state, not persisted email message bodies. Messages are retrieved from the upstream mailbox when requested.

Private-preview honesty

This is not yet a public-production security claim. External security review, public legal surfaces, recovery flows and launch controls remain gates before broad release.