Third Party Index

Snapshot 39699

Document
Security page
URL
https://getfreightbox.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
64449 bytes
SHA-256 (raw)
0a2403786b3cdc532fdd378e258ef9494009a50dcfdecbfc968e4642fd8d748f
SHA-256 (normalized text)
6636ea4a4fa92afae5cbd7b15753078c7214f1a6394c6dddc4934a3c6bf4d41f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
Your email is your paper trail — rate confirmations, claims, and carrier agreements. Here is how we protect it.
CASA Tier 2Independently assessed by TAC Security
GDPR-readyEU data handling, erasure on request
Draft-only AIDrafts replies — never sends on its own
No model trainingYour mail never trains third-party AI
Tenant isolation
Every record is scoped to your organization, and mailbox-level permissions control which team members can read each inbox.
Draft-only AI
AI Mailbox never sends on its own: it creates reply drafts, and your team decides what gets sent from Gmail or Outlook. Programmatic sending exists only through the Platform API, gated behind explicit send scopes that an organization administrator provisions.
No third-party model training
Customer email content is processed to provide the service and is not used to train third-party AI models.
Encrypted credentials
OAuth credentials are stored server-side and encrypted. Raw tokens are never exposed in the UI.
Data minimization
We store the email content your team works with — not transport machinery. Routing chains and signature blobs are stripped at ingest, while authentication verdicts are retained for dispute evidence.
Verified webhooks
Gmail Pub/Sub and Outlook Graph notifications are authenticated before processing.
Independent assessment
Freightbox has been independently assessed under CASA Tier 2 (App Defense Alliance, Web App Profile) by TAC Security, covering our production application and API. All assessment checks passed (August 2026), and Google approved Freightbox’s OAuth app verification for the covered Gmail and Calendar scopes in September 2026. The assessment is renewed annually.
Responsible disclosure
Security researchers can report issues to security@getfreightbox.com. Details, scope, and safe-harbor terms are published in the app’s vulnerability disclosure policy.
Data deletion
Organizations can request full erasure of their data. See the data deletion process and our privacy policy.
CASA Tier 2Independently assessed by TAC Security
GDPR-readyEU data handling, erasure on request
Draft-only AIDrafts replies — never sends on its own
No model trainingYour mail never trains third-party AI
How we protect your email: security · privacy policy