Security at Conduit
Email is the most sensitive data most people have. Here’s exactly how we treat it.
Conduit Mail completed Google’s CASA Tier 2 security assessment — an independent review by TAC Security, a Google-authorized lab.
Verified by Google for restricted Gmail access.
How we protect your mail
- 01
Email renders in a locked-down frame with scripts disabled and every tag sanitized.
- 02
Your tokens and mail-server passwords are encrypted with AES-256-GCM before they touch our database. Everything in transit is TLS.
- 03
Our database refuses direct browser access — every read and write goes through authenticated server code.
- 04
A strict Content Security Policy blocks inline scripts and any origin we didn't allow.
- 05
Your Conduit account has no password to steal — sign-in is Google-only and inherits your Google two-factor and passkeys.
- 06
Every Conduit domain lives on the .app top-level domain, which browsers ship as HTTPS-only — a plaintext connection is refused before the first request leaves your machine.
- 07
CAA records restrict which authorities may issue our certificates, and we watch public Certificate Transparency logs for anything issued outside that list.
- 08
Audited against the OWASP ASVS Level 2 checklist internally — then assessed independently for CASA Tier 2 by TAC Security.
What we store — and what we don’t
We store
- ✓Account identity
- ✓Encrypted OAuth tokens and mail-server credentials (AES-256-GCM)
- ✓Your rules, notes, and settings
- ✓Short writing samples from sent mail (body excerpts in plain text, plus recipient and subject as metadata; on by default, toggle in Settings → Writing style)
- ✓AI usage counters — numbers only, never content
We don’t store
- —Full mailboxes or inbox mirrors
- —Message HTML
- —Attachments
Your mail lives on your device. We never copy your inbox to our servers.
We don’t mirror your inbox. We do store a few small things that make Conduit work the same on every device — your rules, the notes you save, and short writing samples from your sent mail so drafts sound like you everywhere. Writing samples are on by default; turn them off in Settings → Writing style. All of it is visible in Settings, and all of it is yours to delete.
AI and your mail
Never training data
Your email is never used to train AI models. Not by us, not by Anthropic — their commercial API terms forbid it, and Google’s restricted-scope rules bind us to it in writing.
AI features wait to be asked
AI features are yours to invoke — summaries, drafts, search, and chat all wait for you to ask. One thing runs on its own: sorting new mail into six categories. A local classifier on your device does the sorting. On paid plans, the messages it’s unsure about get a second look — just the sender, subject, and a short preview go to Anthropic, never the body. On the free plan, categorization stays entirely on your device and sends nothing.
Verify it yourself
Don’t take our word for any of this. These checks run live against our production domains — anyone can run them, anytime:
- TLS configuration— Qualys SSL Labs
- Security headers— securityheaders.com
- HTTP Observatory— Mozilla
- security.txt— our RFC 9116 security contact
Report a vulnerability
Found a security issue in Conduit Mail? Email us with what you found and how to reproduce it. We read every report sent to the address below. Please report privately and give us a reasonable window to investigate and fix the issue before any public disclosure. We don’t run a paid bug bounty program.
security@conduitmail.appSafe harbor: research conducted in good faith — without accessing mail that isn’t yours, disrupting the service, or destroying data — will not lead to legal action from us over your report. And with your permission, we credit researchers who report valid issues.