Security & privacy

Clear controls before confident claims.

Inlyra names its access model, infrastructure providers, human-control boundaries, and current limits without borrowing credibility from certifications it does not hold.

Delegated access

Permissions follow the signed-in user and are expanded through incremental consent.

Explainable analysis

Important and risky messages are accompanied by reasons and recommended verification steps.

Human control

Consequential actions are not marketed before approval, recovery, and audit boundaries are verified.

Regional infrastructure

Primary application infrastructure runs in Google Cloud europe-west1.

Provider clarity

Microsoft Entra ID, Microsoft Graph, and Google Cloud are the core providers.

Disconnect behavior

Disconnect stops new Microsoft access and deletes token data for the connection.

No badge theatre

Unverified assurance claims stay off the site.

No fake SOC 2, ISO, GDPR certification, penetration-test, audit, customer count, reference, or customer-logo claim is published.

Security contacts
Security reports
security@getinlyra.com
Privacy requests
privacy@getinlyra.com

Questions

Ask directly instead of guessing.

Contact security