Security & data
How the Threadship agent works with your email and files: what it can reach, what it does on its own, where your data goes, and how to switch it off. Questions or a security report: [email protected].
Key terms
- Team: the people in your company who work on shipments together in Threadship. Admins invite them.
- Admin: a team member who manages the team and the agent's settings.
- Agent: Threadship's AI assistant for your team. It reads shipment email, saves documents, keeps records up to date and drafts replies.
- Agent account: the email account your company sets up for the agent, which it uses to read mail and reach shared folders.
- Shipment: one consignment your team handles. Its record holds the details, documents, emails and history for it.
How the agent works with your email and files
The agent works through its own account in your organization (for example [email protected]), which an admin connects. It sees the mail that account receives and the folders shared with it. It doesn't see anyone else's mailbox.
Today Threadship connects to Microsoft 365. The exact permissions are listed under Microsoft 365 below.
What the agent can and can't do
- It can't send email from your mailbox. It writes drafts; a person opens them in their email and sends them. The only email Threadship sends is a notification to a team member who is @mentioned, from a Threadship address.
- Only the folders an admin picks. The agent reads and saves files only inside the folders an admin chooses in its settings. With no folder chosen, it reads and saves no files.
- It doesn't delete or move your files, and it saves new files without replacing existing ones.
- Unknown senders change nothing. The agent acts on mail from your team, on replies to conversations it's already handling, and on senders an admin has approved, such as your suppliers or forwarders. It also checks that their mail really comes from them. Mail from anyone else is held until someone on your team decides whether to use it.
What it does on its own, and what needs you
On its own, the agent links emails and documents to shipments, saves documents into a folder per shipment, updates shipment details and connected spreadsheet rows, and adds to the team memory.
It needs a person to send any email. When a document disagrees with a value someone entered, it asks instead of overwriting it.
Anyone on the team can see what the agent changed on the shipment's timeline, read the team memory, and ask the agent to correct either. A file or folder the agent saved can be undone, as long as nobody has changed it since.
Who sees your shipments
Shipments belong to a team. Only people your admins invite from your own organization can see them; no one outside the team can. Files the agent saves keep the permissions of the folder they're in, so your own file sharing settings decide who can open them.
What Threadship stores
- Shipment records: details the agent extracted or people entered, the shipment timeline, and links to the emails and files behind them (IDs, subject, sender, date).
- Chat messages in Threadship, the team memory, and your team's settings.
- A record of each action the agent takes (what, on which item, when, and the result).
- The agent's working notes for each task, which can include the email or document it worked on. These are encrypted and deleted after 30 days.
Apart from those working notes, Threadship doesn't keep copies of your mailbox or your documents. Documents the agent saves go into your own folders, so your email, documents and spreadsheets stay in your own accounts even if Threadship is unavailable.
Encryption and infrastructure
- Threadship runs on Google Cloud in the United States. Traffic is encrypted in transit (TLS), and stored data is encrypted at rest.
- The agent account's sign-in tokens and the agent's working notes are additionally encrypted with their own keys.
AI processing
The agent runs on Anthropic's Claude models through Anthropic's API. The content a task needs (for example an email, its attachments, the shipment record and the team memory) is sent to Anthropic to produce the agent's response.
Under Anthropic's commercial terms, content sent through the API is not used to train their models by default. Those terms are Anthropic's and may change; if they change in a way that affects your data, we'll update this page. Threadship doesn't train models on your data. Your data belongs to your company.
Microsoft 365
Microsoft asks for these permissions when an admin connects the agent account:
| Permission | Why |
|---|---|
| User.Read | Read the agent account's own profile, to confirm which account was connected. |
| Mail.Read | Read the mail the agent account receives. It can't send, delete or move email. |
| Files.ReadWrite.All | Read and save files the agent account can reach. Threadship limits this to the folders an admin picks. |
| offline_access | Keep working between sign-ins, so new mail is handled when it arrives. |
The agent account must belong to your own Microsoft 365 organization.
Revoking access and deleting data
- In the agent's settings, an admin can remove folders, approved senders and spreadsheets at any time.
- Unsharing a folder with the agent account removes its access to that folder.
- In Microsoft Entra, an administrator can remove Threadship under Enterprise applications, which withdraws its permissions for the whole organization, or disable the agent account.
- To have your organization's data deleted from Threadship, an admin can email [email protected]. We delete it on request.
Security assurance
We are preparing for a SOC 2 Type I audit. For a security questionnaire or more detail, email [email protected].
Subprocessors
We use a small number of service providers to run Threadship: cloud hosting and database (in the US), an AI model provider (Anthropic), background job processing, and email delivery for notifications. A current list is available on request at [email protected].
Your email and file provider (Microsoft 365) is your own; Threadship connects to it with the permissions above.
Reporting a security issue
Email [email protected] with “Security” in the subject. Please give us a chance to fix an issue before disclosing it publicly.