Security at Frank
Last updated: 2 September 2026
Frank reads your email. We are not going to bury that.
You are letting software into the most sensitive thing your business owns. This page explains exactly what Frank can do, what it cannot do, what we keep, and what happens when something goes wrong. If anything here is unclear, ask us — lp.brochu03@gmail.com.
The short version
- Frank drafts. You send. Every reply is a draft in your review queue until you approve it. Automatic sending is off by default and stays off until you turn it on, one narrow situation at a time.
- Some mail is never answered automatically. Ever. Anything touching legal, money, contracts, HR, health, or security goes to you. There is no setting that changes this.
- We do not keep your mail. Message content lives only as long as the draft is open. The permanent record is a decision log, not your inbox.
- Your writing never trains anything shared. Frank learns your voice for your drafts only. No customer's mail is ever used to train a model that another customer touches. That is a contractual commitment, not an intention.
- Disconnect deletes. One click revokes our access, destroys the tokens immediately, and schedules your content for deletion.
What Frank is allowed to do
We ask for the narrowest access that makes the product work, and we ask for it in stages.
When you sign up, Frank asks to read your mail, create drafts, and organize with labels. It does not ask for permission to send. It cannot send. The permission is not there.
Only when you switch on automatic replies for a specific situation — a booking confirmation, a "we received your inquiry" — does Frank ask for send permission. If you never turn that on, we never have it.
We do this because the permission you never granted is the one that can never be misused.
The part most email tools do not have
Frank does not ask an AI model whether it is safe to reply. It decides that before the model is involved, and checks again afterward.
Before the model sees anything
Frank runs a fixed list of deterministic checks. If your mail is about a contract, an invoice, a legal dispute, an HR matter, someone's health, a security incident, or a payment, the message is never sent to a model provider at all. It goes straight to you. This is not a confidence score that can be tuned — it is a list, and it is over-inclusive on purpose. A wrong flag costs you one click. A missed one can cost you your business.
Before anything reaches a model
It is redacted. Personal details are stripped from what leaves our systems.
After the model writes
Every generated reply is screened again before it can go anywhere. Frank blocks any draft that promises something, quotes a price, offers a discount, commits to a deadline, accepts terms, references staffing or termination, contains an unfilled placeholder, leaks its own instructions, or addresses anyone who was not already on the thread.
Twenty-nine separate checks must all pass before a reply can send itself. They cover attachments we could not read, mail that failed authentication, first contact from a stranger, threads where you are the one who owes an answer, monetary amounts, calendar changes, new recipients, rate limits, and your quiet hours. Any one of them fires and the message becomes a draft for you instead.
And there is a two-minute undo window on every automatic send, plus a kill switch in the header of every page that stops all automation across your whole account instantly.
How Frank learns your voice
Frank reads your sent mail once, when you connect your mailbox, and measures how you actually write — your typical reply length, sentence length, how often you use contractions, how you open and close messages, whether you use exclamation marks, the phrases you reuse.
What we keep is the measurements, not the mail. After the profile is built, the sent-mail content used to build it is not retained.
Your profile is yours alone. It is stored per mailbox, never shared between customers, and never combined with anyone else's.
Your mail does not train our models. We do not retain data obtained through the Gmail or Microsoft Graph APIs to develop, improve, or train non-personalized AI or machine learning models. Frank uses your writing to write like you, for you, and for nothing else. We are contractually bound to this by Google and Microsoft policy, and we would do it anyway — a company that quietly pools customer mail into a shared model has no business selling this product.
What we store, and for how long
| What | How long |
|---|---|
| Message content | Only while a draft is awaiting your review, plus your retention window |
| The decision record | Kept: what Frank decided, why, which rules fired, a content fingerprint, a redacted excerpt, the recipients, the outcome |
| Your voice profile | Until you disconnect |
| OAuth tokens | Encrypted at rest with AES-256-GCM; destroyed immediately on disconnect |
The audit trail deliberately does not contain your email. It contains a cryptographic fingerprint and a redacted excerpt — enough to prove what happened, not enough to read your mail. If we are ever compelled to hand over our logs, there is very little in them about you.
Disconnecting revokes our access, deletes the tokens on the spot, stops all processing, and schedules your content for deletion. No retention hostage, no email to support, no waiting period.
Who else touches your data
We use these companies to run Frank. Each is contractually bound not to retain or train on your content:
Right now, nobody does — Frank is not yet processing customer email. When it is, this list will name every provider in full, and it will be published before the first real mailbox connects.
- Anthropic — generates draft text. Zero-retention terms; your content is not used for training. Decided.
- Application and database hosting — not yet selected.
- Error tracking — diagnostics, message content excluded. Not yet selected.
- Transactional email — our notifications to you, never your mail. Not yet selected.
This public website is hosted by Netlify and collects no email data.
This list is current as of 2 September 2026. We will update it here before adding anyone, and notify existing customers.
Can your people read my email?
Almost never, and only with your say-so.
We have a written break-glass procedure. A human at Frank may read your message content only when you have specifically agreed to us looking at a specific message — typically because you have reported a problem with it — or where security or the law requires it. Every access is logged and reviewed.
We do not browse customer mail for debugging, for quality checks, or out of curiosity. The system is built so that we do not have to: the audit trail tells us what happened without showing us what it said.
Where we are on certification
Straight answers, updated as things change:
| Item | Status |
|---|---|
| Google OAuth verification | Not yet submitted. Frank uses Gmail restricted scopes, which requires Google's app verification plus an independent CASA security assessment against the OWASP Application Security Verification Standard, recertified every year. We will not connect an external mailbox before this is complete. |
| CASA assessment | Not yet started. Scheduled to begin alongside Google verification. |
| Microsoft publisher verification | Not yet started. |
| Microsoft 365 Publisher Attestation | Not yet started. |
| SOC 2 | Not yet. We are a small company and we will not pretend otherwise. If you need SOC 2 to buy, tell us — it moves up the list. |
Automated security scanning — static analysis, dependency scanning, and dynamic testing — runs against every change we ship.
If something goes wrong
We have written down what we will do, in advance, so that we cannot quietly decide otherwise in the moment:
- Stop everything. The kill switch halts all automation.
- Find exactly what was affected from the audit trail — the specific messages, not a vague window.
- Tell you which messages. Not a generic "we experienced an incident" email. The actual list.
- Preserve the logs. Audit records are never altered.
- Write the test that catches it, then the fix.
- Publish what happened.
On a product like this, a quiet fix is worse than the incident.
Your controls
- Kill switch — stop all automation instantly, from any page.
- Never-automate list — people and domains Frank will never reply to on its own.
- VIP list — senders that always come to you.
- Quiet hours — times Frank will not send.
- Rate limits — a ceiling on automatic replies per day.
- Per-situation switches — automatic replies are enabled one narrow case at a time, never all at once.
- Disconnect — one click, immediate.
Report a vulnerability
Email lp.brochu03@gmail.com. We respond within 48 business hours. We will not threaten you, we will credit you if you want credit, and we will tell you what we fixed.