Emmy is built for enterprise email. Every architectural decision starts from the question: what is the minimum exposure needed to do this job?
No implicit trust based on network location. Every request is authenticated through verified identity providers before reaching the application.
Emmy requests only the delegated scopes it needs for the task at hand. No standing admin access. No persistent email body storage.
Every action has a tamper-evident receipt. Security scores, routing decisions, draft events, and sends are logged for compliance and retrospective review.
The Emmy portal is protected by Cloudflare Access. The Azure Container App origin does not accept direct internet traffic — it returns 403 to anything that bypasses Cloudflare. Your corporate Entra ID (Microsoft) or Google Workspace identity is the only key.
Emmy reads messages through delegated OAuth or IMAP credentials. Email body content is processed for the duration of a single analysis and not stored in Emmy’s database. Labels, audit events, and structured outputs are stored — raw message content is not.
Each user brings their own OpenAI-compatible AI endpoint and key. Keys are encrypted at rest and stored only as a reference — never returned in API responses. Emmy never shares keys between users and never uses a shared pool API key for customer data.
We take security seriously. If you discover a security issue in Emmy, please report it responsibly. We aim to acknowledge reports within 48 hours and resolve valid issues promptly.
Send your findings to the security contact listed in /legal/security. Please include reproduction steps, impact assessment, and any relevant artefacts.