Security
What Corral can touch,
and what it can’t.
Corral writes as you, from your mailboxes, to people who decide. So the rules that matter are about what it may do without you. Here they are, and where each one lives in the product.
Nothing replies without you.
- Every reply is a draft. Corral writes it from your knowledge base and shows what it cited. You send it, and for 10 seconds you can take it back.
- Never say holds everywhere. Phrases you ban, prices you don’t quote: a draft that trips one can’t be sent, from the app or from any client.
- Sequences check before they launch. Empty fields, a mailbox over its cap, a step with no unsubscribe: launch stops and says which.
- API keys can’t send. API keys can draft but can’t send. Sending needs a signed-in MCP connection.
- Companies and contactsAdd, tag and change a lead’s statusNoneReadWrite
- SegmentsCreate and change segmentsNoneReadWrite
- SequencesRead sequences, steps and resultsNoneReadWrite
- UniboxTriage and save drafts; nothing leaves your mailboxesKeys can draft but can’t send. Sending needs a signed-in MCP connection.NoneReadWrite
- Knowledge baseSearch the knowledge base and Never sayNoneReadWrite
- ScoringRead scores and whyNoneReadWrite
The access picker when you make an API key: the Unibox stops at Write.
Your mailboxes stay yours.
Corral sends from the Google and Microsoft mailboxes you connect, never from a shared pool of ours. Each mailbox has a daily cap and random gaps between sends, and you can take one out of the pool, or disconnect it, at any time. Replies land in your inbox as they always did; the Unibox reads them there.
Cal.com, Phoenix ERP and AutoSend connect with the narrowest permissions each offers, listed before you allow them and again in Settings → Integrations.
Who and what is signed in.
- People sign in with Google or a one-time code sent to their work email. Owners manage the workspace and every API key; members manage the keys they made.
- AI clients sign in as a person. Cursor, Claude and other MCP clients use OAuth, act as whoever allowed them, and see only the tools their access allows.
- API keys are shown once. Corral keeps a hash and the last four characters. Keys expire after 90 days by default; rotating keeps the old one working 24 hours.
- Every call is logged for 90 days, refused ones included, and limited to 60 a minute per key or connection.
Your data.
- Companies, contacts, threads and the knowledge base export as CSV from the app, any time.
- Corral reads public websites to score them. It doesn’t buy lists or enrich from brokers; every contact detail shows where it came from.
- Workspace data is stored in one region, named here.To confirm · Krak
- Encrypted in transit with TLS 1.2 or later, and at rest.To confirm · Krak
- When a workspace closes, its data is deleted after 30 days.To confirm · Krak
- The subprocessors that host and process workspace data, listed with what each does.To confirm · Counsel
Tell us.
Found something? Write to security@corral.app. Tell us how to credit you, if you’d like. Terms, privacy and the data processing agreement are under Legal.