Skip to main content
Slashy handles your email, calendar, and contacts. Security is the foundation, not a feature.

Certifications

CertificationStatus
SOC 2 Type IIAudited annually
CASA Tier 2Google Cloud Application Security Assessment — passed
Penetration TestingQuarterly, independent third-party firm
EncryptionAES-256 at rest, TLS 1.2+ in transit
Full compliance docs: trust.delve.co/slashy

AI and Your Data

Does the AI train on my emails? No. Every AI provider is contractually bound to a zero-training agreement. Your data is processed to generate a response and then discarded.
AI ProviderUsed ForTrains on Your Data?
Anthropic (Claude)Drafts, agent, automationsNo — contractually prohibited
OpenAIDrafts, editing, autocompleteNo — contractually prohibited
Google (Gemini)Categorization, searchNo — contractually prohibited
GroqFast inference tasksNo — contractually prohibited
Only the minimum necessary context (email thread, memories, calendar if relevant) is sent to providers.

Prompt Injection Protection

Malicious emails can contain hidden instructions to trick AI assistants. Slashy sanitizes and isolates incoming email content from system instructions before it reaches any model. The agent cannot take unauthorized actions and flags suspicious content.

What Data Slashy Stores

  • Email metadata and content — cached for fast access
  • Calendar events — synced from Google Calendar
  • Agent conversations — your AI sidebar chat history
  • Memories — preferences, contacts, writing style
  • Automation logs — what ran and when
  • Usage analytics — anonymous, via PostHog
All stored data: AES-256 at rest, TLS 1.2+ in transit.

OAuth Access Model

  • Slashy never sees or stores your Google password
  • You grant specific permissions you can revoke anytime at myaccount.google.com/permissions
  • OAuth tokens stored encrypted, refreshed automatically
  • Same model applies to optional integrations (Zoom, Granola)

Data Deletion Timeline

StepTimingWhat Happens
Revoke accessImmediateOAuth tokens invalidated. No more email/calendar access.
Hard deleteWithin 24 hoursAll data permanently deleted from production.
Backup purgeWithin 7 daysData removed from encrypted backups.
Delete your account from Settings > Account or email founders@slashy.com.

Enterprise Security FAQ

Encrypted servers in the United States, hosted on AWS with SOC 2 compliance.
No. Employee access to production data is restricted, logged, and auditable. No one reads your email unless you explicitly share it for debugging.
Yes. Visit trust.delve.co/slashy to request the full report, pen test summary, and compliance documents.
Yes. Email founders@slashy.com with details. We respond within 24 hours.

Connecting Gmail

OAuth permissions and what Slashy accesses.

Your First Week

Day-by-day onboarding guide.