Control your access. Protect your work.

Understand what Elite can access, what it stores, and how you control it. Manage your inbox connections, team permissions, shared documents, and AI access.

Scoped accessTeam permissionsData controls

Security across the account, workspace, and service

Account access

Hashed credentials, optional authenticator MFA, device management, short-lived installation tokens, and rotating refresh credentials.

Tenant and team boundaries

Tenant-scoped APIs and role-based team permissions keep workspace access tied to an authenticated account and approved role.

Transport and service hardening

TLS in transit, rate limits, hardened non-root services, least-privilege service accounts, and security-focused response headers.

Recovery

Database integrity monitoring, backup procedures, and recovery checks support dependable operation.

Auditability

Security and administrative actions produce audit history so teams can review sensitive changes and access-related events.

Data minimization

Standard tracking sends message metadata rather than message bodies. Stored content and files enter the suite through deliberate product workflows.

A clear purpose for the data you share.

  1. Standard tracking records normalized message, recipient, delivery, and event metadata. Message bodies are not part of the standard tracking payload.
  2. Explicit workflows store the templates, campaign content, recordings, documents, and signature material a user chooses to create or upload.
  3. Signal classification keeps likely-human, privacy-protected, automated scanner, sender, and unknown activity distinct with clear labels for each activity type.
  4. Retention and deletion are described in the privacy policy and DPA, including separate treatment for network and approximate-location fields.

Your connections, your choices.

What can a connected inbox access?

Provider authorization shows the requested access. The connection supports the mailbox features you enable; standard tracking and stored campaign or document content have different data needs.

Can an assistant send for me?

AI reading, drafting, and sending use separate permissions. Tracked AI messages and campaign launches require review of the prepared send. Configured workflows follow their authorization rules.

Who controls team AI access?

Owners and admins set role limits. A connection cannot grant more access than the user and team allow.

Can I see what happened?

Review recent connection activity and workflow history. Check the action and its result before deciding what to do next.

How do I stop access?

Disconnect the provider or AI connection, pause the workflow, or revoke a document link. Revocation does not recall an already sent email or downloaded file.

What can I delete?

The privacy policy and DPA explain retention and deletion, including different treatment of tracking metadata, uploaded content, and operational records.

Security information for your review

These controls are not a claim of SOC 2, ISO 27001, or another independent certification. Enterprise evaluators may request current architecture, access-control, recovery, and vulnerability-management information under appropriate confidentiality terms.

Report a suspected vulnerability privately

Use the support contact and include enough detail to reproduce the issue. Do not access other users’ data, disrupt the service, or perform destructive testing. Credible reports are acknowledged and coordinated through remediation and disclosure.

Contact security

Send with context. Follow through with confidence.

Connect your inbox, track the work that matters, and give every important conversation a next step.