Security at Freightbox
Freightbox protects logistics inboxes with draft-only AI, encrypted credentials, provider webhook verification, and organization-scoped access controls.
Draft-only AI
AI Mailbox creates reply drafts, but users decide what gets sent from Gmail or Outlook.
No third-party model training
Customer email content is processed to provide the service and is not used to train third-party AI models.
Encrypted credentials
OAuth credentials are stored server-side and encrypted. Raw tokens are never exposed in the UI.
Verified webhooks
Gmail Pub/Sub and Outlook Graph notifications are authenticated before processing.
Least privilege
Mailbox setup and cleanup actions are restricted to mailbox owners or organization admins.
Responsible disclosure
Security researchers can report issues through our vulnerability disclosure process.
Tenant isolation
Every record is scoped to your organization, and mailbox-level permissions control which team members can read each inbox.
Data minimization
We store the email content your team works with — not transport machinery. Routing chains and signature blobs are stripped at ingest, while authentication verdicts are retained for dispute evidence.
Independent assessment
Freightbox has been independently assessed under CASA Tier 2 (App Defense Alliance, Web App Profile) by TAC Security, covering our production application and API. All assessment checks passed (August 2026); the Letter of Validation is being issued and submitted to Google.
AI Mailbox data flow
Users connect Gmail or Outlook with OAuth. Freightbox syncs inbound mail, classifies logistics workflow labels, stores internal decision evidence, and writes provider drafts only when the message requires a response.