Trust
We handle your email and messages with the same care you give your most sensitive client conversations.
Connecting mail
Gmail and Outlook connect over OAuth 2.0 only. You grant access through Google or Microsoft, we never see or store your password, and you can revoke the grant at any time from your Google or Microsoft account. Sektra asks only for the permissions it needs: to read and label mail, and to send the messages your team writes.
Connecting WhatsApp
WhatsApp numbers connect through your own WhatsApp Business API provider. The provider credentials you give us are encrypted with AES-256-GCM before they are stored, and the key lives only on our servers, never in the database. Inbound webhooks from the provider are verified before anything is processed.
Encryption
Everything moves over TLS 1.2 or higher, between your browser and Sektra and between Sektra and Google, Microsoft, your provider and our own services. Message content, attachments, the database and backups are encrypted at rest with AES-256.
Where data lives
Application servers, message storage and AI processing run in Amazon Web Services in the United States. The memory layer runs on servers we operate inside AWS. Data is not stored on laptops or in third-party tools beyond the providers listed in our privacy policy.
AI processing
Your data is sent to a model to produce a result and is not retained by the model service, not shared with the companies that built the models, and never used to train anything. We do not train our own models on customer data either.
Access inside your workspace
Access is granted per inbox, so a member sees only the inboxes they have been given. Roles decide who can invite people, manage integrations and handle billing. Only the workspace owner can change the plan or payment details.
Access on our side
Production access is limited to a small number of named engineers, over key-based access, and is used only to operate the service or for support you have asked for. We do not read customer data.
Application security
Sign-in is handled by Clerk with short-lived session tokens. Every request is checked against the caller’s workspace and role, and assistant runs are rate limited per user. Payment webhooks are verified by signature and timestamp, and card details never touch our servers. Errors are monitored and reviewed.
Deletion
Disconnecting an inbox stops syncing and removes it from the workspace. When a workspace is deleted, everything in it, including message content, attachments, derived data and the memory layer, is permanently deleted within 30 days. Backup copies expire on the rotation schedule after that.
Compliance
We follow the Google API Services User Data Policy, including the Limited Use requirements, for all Gmail data, and the equivalent Microsoft terms for Outlook data. A data processing agreement and a security review are available with an Enterprise plan.
Reporting a vulnerability
If you find a security problem in Sektra, email hello@sektra.ai with enough detail for us to reproduce it. We acknowledge every report within 48 hours and keep you informed.