Most AI sales tools describe safety in adjectives. This page describes ours in mechanisms — each one enforced in code, each one visible in the product. If a claim on this page ever stops being true, the product stops working that way too, loudly.
New accounts run in approve-first mode: every email waits for a human click. Autonomous mode unlocks only after 20 human-approved drafts — and even then it stays a visible switch the client can flip back any moment.
An address that fails multi-step verification is never emailed. There is no override flag.
A hard cap on daily sends per account, plus dedupe against everything already sent — the same address or domain is never hit twice by accident.
Domain-auth failure, hard bounces, or sender-health drift stop the system by itself — and it tells you it stopped. It never degrades quietly.
Robert drafts connection notes and comments; a human sends them from their own account. Your LinkedIn account is not ours to risk. Same for WhatsApp — drafts only.
Every factual claim in a brief must carry a URL and a date. A brief with an unsourced fact fails validation and never reaches your screen. Facts and inferences are typed separately and never mix.
Every performance figure we publish includes numerator, denominator and period, from our own production system. We consider an undated, denominator-free "80% improvement" a red flag — in anyone's marketing, including ours.
Client data lives in Postgres with row-level security enabled and zero client-side grants: a browser session cannot read the database directly at all — every read passes through the API, which resolves your identity server-side.
What Robert learns from your approvals, edits and ratings calibrates your hunt only. Nothing about your pipeline, contacts or drafts feeds any other client.
Every decision, edit, send, block and mode change is timestamped with an actor and a reason. Any morning can be reconstructed event by event — including the emails that were not sent, and why.