Security overview

Handle business email with a narrow, visible boundary.

Microsoft work-account sign-in, explicit mailbox permission and access controls keep your company in charge of its email.

Identity

Microsoft work accounts

Application sign-in and mailbox authorization are separate. Unknown organizations and uninvited users are denied.

Personal mailbox

Delegated read access

A personal connection requests Microsoft User.Read, Mail.Read, and offline access. It does not request application-wide mailbox access.

Shared mailbox

A separate narrow permission

A shared connection requests delegated Mail.Read.Shared and offline access, then verifies access to the configured mailbox before saving the connection.

Outlook actions

Read-only Outlook access

Smart Inbox does not request Mail.ReadWrite or Mail.Send and does not call Graph endpoints that change Outlook mail.

Application access

Mailbox membership still applies

Microsoft permission is necessary but not sufficient. The application separately controls which members may view or work with a mailbox.

Human control

Suggestions remain reviewable

People can correct priority, category, and workflow decisions. Draft suggestions do not send themselves.

Data handling

Mirror what the workspace needs.

The product design mirrors message text and metadata into the application database. Attachment metadata is recorded, while eligible attachment files are requested from Microsoft 365 when an authorized member opens them.

AI review boundary

  • AI output may be incomplete or wrong
  • AI features can use selected message text, metadata and business context
  • Attachment files are not part of the current classification request
  • Human corrections take priority over later AI suggestions
  • No AI feature may send or change Outlook mail in Smart Inbox

Assisted setup

Check access before the trial begins.

We confirm the participating users, selected work or shared mailbox and applicable service terms, then check the connection and workspace before starting the 14-day trial. A website request does not connect Outlook.

No unsupported certifications

Ashby does not currently claim SOC 2, ISO 27001, PCI certification, a penetration-test result, a guaranteed uptime level, or legal compliance certification for Smart Inbox.

No blanket location promise

East US 2 is the current staging resource region, not a blanket promise for production storage, backups, support access, Microsoft 365 processing, or future AI processing.

Optional replies are being prepared for the pilot

The currently released connection is read-only. We are preparing optional replies for both trial and paid users, subject to legal review and release checks. Before enabling replies, each person will see a separate disclosure and Microsoft permission screen for delegated read/write and send access. These Microsoft permissions are broader than replying.

Smart Inbox will create the reply draft in Outlook, show the sender, recipients and message for review, and require a separate Send confirmation. It will not send automatically. Once a send is submitted, delivery may occur and recall is not guaranteed. A person can keep using read-only access without enabling replies.

These changes will be reflected in the service documents before customers are asked to grant reply access.