Security & safety

The speed of an agent, with a human in the loop

An AI with access to your email and files has to be trustworthy first. Nevlar prepares work and holds anything consequential for your approval.

Try Nevlar free →

Never auto-sends

No email, file share, or payment happens without your explicit approval.

Scam & fraud detection

Flags wire-fraud (BEC), gift-card scams, phishing, and impersonation — and refuses to draft a reply to a flagged sender.

Prompt-injection containment

Untrusted email/file content is sanitized before the AI reads it, including unicode-homoglyph tricks.

Encrypted credentials

OAuth refresh tokens encrypted at rest (AES-256-GCM).

Impersonation defense

Detects a known contact's name arriving from a stranger's address.

Layered defense

Zero-trust checks, circuit breakers, behavioral anomaly detection, and targeted-attack alerting.

FAQ

Can Nevlar send an email or move money without me?

No. Everything outbound is prepared as a draft or proposal and requires your explicit approval.

What happens if I get a phishing or wire-fraud email?

Nevlar flags it and refuses to draft a reply to a flagged sender, warning you instead.

Are my Google/Microsoft credentials safe?

Your OAuth refresh tokens are encrypted at rest with AES-256-GCM.

Nevlar does the work — you approve it

Email, calendar, docs, research, automations, and a proactive agent, across Google and Microsoft.


Open Nevlar