Some email is written to trick your assistant
The moment an AI reads your inbox, anyone who can email you can try to give it orders. Anjal checks every incoming message for that, and holds the dangerous ones back before your assistant ever sees them.
no waitlist, no setup, nothing to turn on
What a person skims past, a model carries out
This is the shape almost every attack takes. An ordinary looking email with instructions buried in it that only software ever reads.
Hi,
Thanks for the order. Our bank details changed this month, so the attached invoice has the new remittance information on it. Could you use those from now on?
Happy to jump on a call if anything looks off.
Priya
Looks like an ordinary supplier email. Switch the view to see what your assistant reads.
Three things happen to that email
It arrives, as normal
We accept the mail first and check it after. Your MX record is untouched, nothing bounces, and nothing goes missing. The sender sees an ordinary delivery.
Two checks, made separately
One looks for the tricks these messages use, including text hidden from the reader. The other is a model asked a single question: is this trying to direct an assistant? They have to agree.
It is held back, not deleted
When both agree, the message is hidden from every route an agent can use, and it waits for you. You can read it, and only a person can release it. An agent cannot release its own quarantine.
Why two checks and not one: either alone would either miss attacks or cry wolf on ordinary mail. Across 562 real messages, the combination matched exactly one, and it was a genuine attack.
What else is watching
Viruses never reach the mailbox
Infected mail is refused while the sender is still connected. It is not filed away in a folder for someone to open later; it is never stored at all.
Your assistant's replies are checked too
Before a reply goes out we check whether it is following instructions that came from the email it is answering, or about to include a key or password.
Your systems are told
Anything suspicious raises an event your own tools can act on, whether it was held back or merely flagged. You are not relying on somebody noticing.
It is your switch
Protection is on from the first email. You can turn it off for the account from your dashboard, and turn it back on, at any time.
We try to break it on purpose
The uncomfortable part of using a model as a guard is that the thing it is judging gets to write to it. So we keep a test that tries to talk it round: emails carrying fake approval lines, invented claims of a prior security review, and notes addressed to the checker itself telling it to answer no. We run the same checks with the questions asked in a different order, because a guard whose answer depends on the order of its own options is not a guard.
Last run, 23 September 2026: none of it moved the verdict, and both orders gave the same answer. The model version is pinned, so it cannot change under us without us noticing.
We do not publish the exact rules or thresholds, for the obvious reason.
What this is not
- It is not a spam filter. Spam and junk are handled separately, and filed where you would expect. This is about instructions aimed at software.
- Nothing is deleted. A held message is still yours, still in the mailbox, still readable by you. Releasing it takes one click.
- We do not train anything on your mail. The check asks one question about one message and keeps the answer. That is the extent of it.
- No guard catches everything. That is why your assistant works in the same inbox you read, why replies can wait for your approval, and why anything unusual reaches you rather than being handled quietly.
Give your business email its own assistant, safely
Every plan includes this, from five dollars a month. There is no separate security tier and nothing to request access to.
Want the engineering detail? We wrote up how the quarantine was built and calibrated.