Security

Your inbox deserves serious protection.

Security and privacy are built into the architecture — from how accounts connect to what we allow into our logs.

Encryption by default

Traffic is encrypted with TLS. Sensitive data and provider credentials are encrypted at rest, and access is tightly controlled.

Encryption by default

Traffic is encrypted with TLS. Sensitive data and provider credentials are encrypted at rest, and access is tightly controlled.

Tenant isolation

Row-level authorization separates every account. Automated tests continuously verify that users cannot cross tenant boundaries.

Tenant isolation

Row-level authorization separates every account. Automated tests continuously verify that users cannot cross tenant boundaries.

Content-free telemetry

Our telemetry schema excludes message bodies, subjects, snippets, addresses, names, and attachment filenames.

Content-free telemetry

Our telemetry schema excludes message bodies, subjects, snippets, addresses, names, and attachment filenames.

Tracking protection

Remote images are proxied through an SSRF-safe boundary, and known spy pixels are removed before they can call home.

Tracking protection

Remote images are proxied through an SSRF-safe boundary, and known spy pixels are removed before they can call home.

Our approach

Least access. Clear boundaries.

Aero sits on top of a mailbox you already own. Every decision below is about asking for less, and being able to show it.

Mailbox connections

Aero requests only the provider permissions needed to sync and send mail. Connection tokens are kept in a dedicated secret store and are never exposed to the browser.

The unverified-app warning

Reading Gmail requires a Google restricted scope, and restricted-scope verification comes with an annual third-party security assessment we have not yet completed. Until we do, Google shows an “unverified app” screen when you connect Gmail, and limits this project to 100 Gmail accounts for its lifetime. We would rather run a capped beta and tell you why than route your mail through somebody else’s verified app.

AI isolation

AI features require affirmative opt-in, use bounded content, and are separated by purpose. We do not use inbox data to train generalized models.

Secure development

Security-sensitive behavior is covered by automated authorization, redaction, webhook-signature, and network-boundary tests. Dependencies are reviewed and updated continuously.

Responsible disclosure

If you believe you have found a vulnerability, email security@aeromail.ai with reproduction steps and potential impact. We acknowledge reports within two business days and keep you updated through resolution. The full policy, including scope and safe harbor, is on the vulnerability disclosure page.

Connect it when you’re ready.

Aero works with the Gmail or Outlook account you already have, and every claim on this page is one you can hold us to.