spectre Launch
Trust & Compliance Protocol

Security
Whitepaper.

spectre is built on zero-server persistence of inbox content and rigorous security reviews.

Privacy-first architecture keeps email bodies under your control; sensitive steps run in isolated, encrypted channels.

Every component minimizes exposure while supporting audits and erasure workflows.

CASA Tier 2

Cloud Application Security Assessment
Certified

CASA Tier 2 aligns with Google’s cloud application security expectations for assessed builds.

  • No long-lived storage of OAuth secrets on our edge for client-only flows.
  • Core UX runs in the browser sandbox you control.
  • Ephemeral serverless invocations for AI with keys off-client.

Local-First Arch.

Privacy by Design (PbD)

We avoid centralizing mailbox content to “protect” it—you keep the data plane.

0Inbox Bodies on Our DB
100%User-Controlled Send Path

tls 1.3 encryption

TLS protects data between your browser, providers, and our serverless endpoints.

Modern cipher suites for API traffic.

local processing

Header analysis is engineered to stay on-device during scans.

No bulk upload of mailbox dumps.

serverless isolation

AI calls run in short-lived functions with keys in environment secrets.

Keys are not bundled to browsers.

oauth 2.0 authentication

Least-privilege scopes; tokens live where your integration stores them.

Revoke anytime with the provider.

minimal data retention

We store only operational account metadata needed for billing and caps.

Data minimization by design.

zero-knowledge design

We do not read message bodies for identification—headers only.

Content stays opaque to our logic.

Data Flow Architecture

1

Provider Connection

You authorize OAuth; tokens stay client-side where architected.

2

Local Metadata Extraction

Headers are fetched and processed for patterns.

3

AI Analysis (Serverless)

Minimized signals go to isolated functions calling AI APIs.

4

Erasure Transmission

Notices send from your mailbox with you in the loop.

Compliance & Standards

GDPR Compliance

Facilitation tooling with strict minimization; not a law firm.

Security Standards

TLS, OAuth, serverless isolation, and documented review processes.

Return to Command