Skip to content
Enterprise Governance & ComplianceSOC 2 & GDPR Aligned

Security & permissions governance for AI outbound mail at enterprise scale

Manage the blast radius of autonomous systems with scoped API credentials, cryptographically signed audit logs, recipient fencing, and automated compliance controls.

3,000 emails/month freeZero credit card requiredSub-20ms edge latency
0% (Never trained)
Model Training
Zero customer data training
Immediate
Key Revocation
The next request with that key is refused
6,000 / mo
Free Tier
Security included on all plans
Developer Ergonomics

Drop into your application in under 60 seconds

Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.

$npm install sadasend
agent-security-policy.ts
typescript
TYPESCRIPT
import { SadaSend } from 'sadasend';

const sadasend = new SadaSend(process.env.MASTER_ADMIN_KEY);

// Provision scoped agent key with immutable governance constraints
const agentKey = await sadasend.keys.create({
  name: 'billing-agent-eu',
  scopes: ['emails:send'],
  allowedRecipients: ['*@corporate.eu', '*@invoices.local'],
  rateLimit: { maxPerMinute: 15, maxPerDay: 500 },
  ipAllowlist: ['198.51.100.0/24'],
  requireApproval: false,
});

console.log('Created scoped key ID:', agentKey.id);

Programmatic key provisioning with scoped permissions, IP CIDR boundaries, and rate ceilings.

Core Infrastructure

Engineered for high deliverability and zero incident risk

Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.

Least-Privilege Scoped Keys

Issue granular API keys restricted strictly to sending, viewing logs, or reading templates without administrative access.

IP CIDR Network Fencing

Restrict API key usage to specific VPC subnets or agent server clusters, blocking stolen credential abuse.

Cryptographic Audit Logging

Every outbound transmission records client IP, authenticated key ID, agent model tags, and delivery timestamps.

Multi-Tenant Isolation

Partition email streams, suppression lists, and deliverability metrics across separate development environments.

Zero Data Training Policy

SadaSend strictly never trains machine learning models on customer email contents, recipient addresses, or metadata.

Automated Incident Revocation

Instant global token invalidation halts compromised agent keys in under 5 milliseconds across edge nodes.

Architectural Comparison

SadaSend vs Legacy Enterprise Relays (SendGrid / Amazon SES)

Legacy email relays lack agent identity tracking, IP binding per key, and autonomous loop defense.

Feature & CapabilitySadaSendLegacy Enterprise Relays (SendGrid / Amazon SES)
Per-Key IP CIDR AllowlistingAccount-wide only
AI Model & Agent ID Telemetry
Per-Key Allowed Recipient Domains
Zero LLM Data Training GuaranteeVague terms
Real-Time Circuit Breaker InvalidationImmediate — the next request is refusedMinutes or manual
Forever Free Developer Tier6,000 sends ($0)Trial or credit card
Forever Free Tier
Transparent Economics

Start with 3,000 emails every month at zero cost

No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.

3,000 dispatches monthly forever with zero credit card
All safety gates, allowlists, and velocity limits included
Scale seamlessly: Starter ($12/mo for 10k), Pro ($19/mo for 50k), Scale ($79/mo for 250k)
Free Developer Plan
$0 / mo

No credit card required

Create Free AccountCompare all paid plan tiers
Frequently Asked Questions

Everything you need to know about AI agent email security

Clear, transparent answers on deliverability, API authentication, and rate limits.

Absolutely not. SadaSend operates under a strict Zero Data Training policy. Your email bodies, recipient addresses, and metadata are never used for model training.
Technical Deep Dives

Related developer guides and architectural tutorials

Explore step-by-step production implementation blueprints, benchmarks, and protocols.

Documentation

AI coding agent rules (AGENTS.md, Cursor, Claude)

Setup instructions and rule files for AI coding agents: AGENTS.md, .cursorrules, CLAUDE.md, and hosted MCP configuration.

Read guide
Documentation

Official Client SDKs (TypeScript & Python)

Official zero-dependency client SDKs for SadaSend. TypeScript and Python packages are live on npm and PyPI with typed results and auto-idempotency.

Read guide
Documentation

REST API Reference & Endpoints

Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.

Read guide
Deep Dive2 min read

Email Threat Modeling for SaaS: Preventing Compromised API Key Abuse

What happens when an engineer accidentally commits an email API key to a public GitHub repo? Here is the threat model and defense blueprint.

Read tutorial
Deep Dive3 min read

How to Safely Let Agents Send Email: Defense-in-Depth for Autonomous Outbound

An engineering guide to defense-in-depth for autonomous email: preventing indirect prompt injection, infinite retry loops, and unverified recipient spam.

Read tutorial
Deep Dive2 min read

Securing MCP Servers with Scoped OAuth and Per-Agent Permission Limits

As AI agents gain access to email, databases, and internal APIs via MCP, securing the server against prompt injection and privilege escalation is essential. Here is the defense architecture.

Read tutorial
Deep Dive5 min read

What actually happens when you give an AI agent your email API key

Every email MCP server on the market hands your agent the full platform. That is a capability claim with no control story — and it is the reason your engineering lead keeps saying no.

Read tutorial
Deep Dive4 min read

Prevent Staging Email Leaks: Recipient Allowlist Guide

A single test script or database seed in staging can accidentally blast thousands of fake password resets to real customers. Here is how to engineer zero-leak staging pipelines.

Read tutorial