Trust Center
Inbox handles your customers' messages and your store's order data. Everything a security or vendor review needs — security, privacy, legal, status, and AI governance — in one place.
Compliance posture
Where we stand — honestly
We show only what's true today. No fabricated badges.
| GDPR (EU/UK) | Compliant | DPA, SCCs/UK Addendum, full data-subject rights. |
| India DPDP Act | Compliant | Built to the Act's principles from day one. |
| CCPA / CPRA | Supported | Access, deletion, and no-sale of personal data. |
| SOC 2 | Planned | On our roadmap as we scale; not yet certified. |
| Card data (PCI) | Handled by processors | Stripe & Razorpay handle cards — we never store them. |
AI governance
How we keep the AI safe
AI support fails when a bot says the wrong thing. Here's how Inbox is built so that can't reach a customer.
Approval-first for public v1 — a human approves before any reply reaches a customer.
Grounded in your real order data, not guesses, so answers are specific to the customer.
Every draft is checked for personal data, policy violations, and prompt-injection before you see it.
Customer email is treated as untrusted data, never as instructions to the AI.
Your support content is not used to train third-party AI models.
A live audit counter proves how many replies were sent without your approval — it stays at zero.
Running a vendor security review or need our DPA counter-signed? security_inbox@theagenticgroup.dev — we answer security questionnaires directly.
Bring every support decision into one workspace.
Inbox drafts with Shopify context, knowledge proof, preflight checks, and approval routing before anything reaches a customer.

