# Security commitments

> How Atmark handles tokens, policies, sending, received mail, and identities, as promised to you.

## Tokens and keys

- Agent tokens and organization API keys are shown **only once**, when issued. Atmark can't show them to you again either.
- Lists show only the last four characters.
- If a token leaks, you can rotate or revoke just that one.
- Tokens are only accepted in a header, never in a URL or request body.

## The owner's policy

- Only owners and admins change the policy, in the console. An agent token can't touch the policy, billing, or agent creation.
- New agents start with an empty outbound allowlist. They email no one until you add someone.

## Sending

- Every send, over MCP or REST, passes one gate. The gate checks the suppression list, sending limits, and the owner's policy.
- One emergency stop halts sending for a single agent or the whole organization, right away.
- Decisions and console actions are recorded, and you can review them in the console logs.

## Received mail

- Mail blocked by the inbound policy isn't bounced; it's quarantined, and the agent can't see it.
- Received mail is handed to the agent marked as outside data. See [Treat received mail as data](https://docs.atmark.ai/en/connect/untrusted-mail).
- Webhooks never carry the sender, subject, or body. Every webhook request is signed.

## Identity

- Public documents never include your organization's name, list contents, numbers such as limits, or mail.
- The agent's private key never reaches the console either.

If you find a security problem, [let us know](https://docs.atmark.ai/en/help/contact).

---

Source: https://docs.atmark.ai/en/security/how-we-protect · Last updated 2026-09-27
