Verify the edge of the system
Inbound mail, account connections, and provider events need signature verification and bounded parsing.
- Signature verification
- Public route inventory
- Attachment policy







A go-live checklist for sender domains, signed inbound routes, secrets, MFA, tenant isolation, and executor gates.
Security readiness is checked before traffic.
Side effects pass through policy gates.
Teams can revisit posture as projects change.
Inbound mail, account connections, and provider events need signature verification and bounded parsing.
Tenant access, prompt boundaries, and executor gates protect customer data and prevent unreviewed side effects.
These pages describe the product contract behind the UI, not a decorative brochure. Each surface should connect back to the same governed support loop.
Public routes verify signatures before processing.
Support moves through secure ingest, AI preparation, human approval, outbound execution, and audit evidence.
Provider setup, project policies, knowledge trust, retention, and billing limits decide how this behaves for a real workspace.
These external links point to provider documentation, privacy notices, data-processing terms, or platform terms that shape production operation.