Trust & Safety

Not promises. Mechanisms.

Most AI sales tools describe safety in adjectives. This page describes ours in mechanisms — each one enforced in code, each one visible in the product. If a claim on this page ever stops being true, the product stops working that way too, loudly.

What leaves the building — and what can't

Approval is the default, not a feature

New accounts run in approve-first mode: every email waits for a human click. Autonomous mode unlocks only after 20 human-approved drafts — and even then it stays a visible switch the client can flip back any moment.

Enforced server-side: the API refuses to switch an account to autonomous below the threshold. The button in the dashboard has no say in it.

Verified addresses only

An address that fails multi-step verification is never emailed. There is no override flag.

Two locks: the brief validator rejects an email action on an unverified contact, and the send gate re-checks at send time. In live traffic this gate has blocked sends — the audit trail shows each one.

Five a day is a ceiling

A hard cap on daily sends per account, plus dedupe against everything already sent — the same address or domain is never hit twice by accident.

Cap and ledger-dedupe run in the send path itself, not in the agent's instructions. An agent cannot talk its way past them.

Automatic Safety Pause

Domain-auth failure, hard bounces, or sender-health drift stop the system by itself — and it tells you it stopped. It never degrades quietly.

LinkedIn is never automated

Robert drafts connection notes and comments; a human sends them from their own account. Your LinkedIn account is not ours to risk. Same for WhatsApp — drafts only.

Evidence discipline

A fact without a source is rejected

Every factual claim in a brief must carry a URL and a date. A brief with an unsourced fact fails validation and never reaches your screen. Facts and inferences are typed separately and never mix.

claims[0] is a FACT without evidence (url+date) → HTTP 422

Published numbers carry denominators

Every performance figure we publish includes numerator, denominator and period, from our own production system. We consider an undated, denominator-free "80% improvement" a red flag — in anyone's marketing, including ours.

Your data

Tenant isolation, enforced by the database

Client data lives in Postgres with row-level security enabled and zero client-side grants: a browser session cannot read the database directly at all — every read passes through the API, which resolves your identity server-side.

No cross-client learning

What Robert learns from your approvals, edits and ratings calibrates your hunt only. Nothing about your pipeline, contacts or drafts feeds any other client.

A replayable audit trail

Every decision, edit, send, block and mode change is timestamped with an actor and a reason. Any morning can be reconstructed event by event — including the emails that were not sent, and why.

Questions about any mechanism on this page: aviel@agentsela.com. Built by Agent Sela · Israel. · עברית ←