Skip to content
Agent Security & Safety PerimeterPrompt Injection Defense

Email infrastructure engineered with agent safety gates and human approval holds

Shield your customer base and sender reputation from malicious prompt injection, infinite recursion loops, and unauthorized email dispatches by autonomous AI agents.

3,000 emails/month freeZero credit card requiredSub-20ms edge latency
100% Boundary
Exfiltration Defense
Enforced allowlists
< 1 Click
Approval Queue
Web dashboard review
6,000 Sends
Monthly Free
Zero credit card
Developer Ergonomics

Drop into your application in under 60 seconds

Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.

$npm install sadasend
agent-safety-policy.json
json
JSON
{
  "keyName": "customer-support-agent",
  "policy": {
    "allowedRecipientDomains": ["mycompany.com", "partner.io"],
    "maxEmailsPerHour": 50,
    "requireHumanApproval": true,
    "blockExternalAttachmentUrls": true,
    "emergencyKillSwitch": "active"
  }
}

Declarative JSON safety policy applied to agent API keys to prevent prompt injection data exfiltration.

Core Infrastructure

Engineered for high deliverability and zero incident risk

Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.

Prompt Injection Quarantine

Isolate outbound emails generated from untrusted inbound user inputs until safety checks pass.

Human-in-the-Loop Gatekeeper

Flag dispatches matching high-risk heuristics for manual human review in /app/approvals.

Velocity Tripwires

Hardware-enforced rate ceilings immediately halt dispatch if an agent attempts more sends than its configured burst limit.

Recipient Boundary Containment

Enforce per-key wildcards (e.g. *@trusted.org) so compromised LLMs cannot exfiltrate data to attacker mailboxes.

Automatic Content Sanitization

Detect and strip dangerous script tags and malformed HTML payloads before SMTP submission.

Real-Time Kill Switch

Disable an agent's email capabilities instantly via dashboard or REST API without revoking other service keys.

Architectural Comparison

SadaSend vs Standard Email Providers (SendGrid / Resend)

Standard providers treat all API requests equally, offering no protection when an LLM is hijacked.

Feature & CapabilitySadaSendStandard Email Providers (SendGrid / Resend)
Prompt Injection Exfiltration Shield
Per-Key Allowed Recipient Domains
Automated Velocity Tripwires
Human Approval Workflow (/app/approvals)
Content Safety Pre-Flight ScansBasic spam filter
Free Tier with Safety Controls6,000 / mo includedNo agent controls
Forever Free Tier
Transparent Economics

Start with 3,000 emails every month at zero cost

No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.

3,000 dispatches monthly forever with zero credit card
All safety gates, allowlists, and velocity limits included
Scale seamlessly: Starter ($12/mo for 10k), Pro ($19/mo for 50k), Scale ($79/mo for 250k)
Free Developer Plan
$0 / mo

No credit card required

Create Free AccountCompare all paid plan tiers
Frequently Asked Questions

Everything you need to know about safe email for AI agents

Clear, transparent answers on deliverability, API authentication, and rate limits.

Attackers can embed indirect prompt injections into inbound emails or web forms, commanding the agent to email confidential database dumps to an attacker-controlled inbox.
Technical Deep Dives

Related developer guides and architectural tutorials

Explore step-by-step production implementation blueprints, benchmarks, and protocols.

Documentation

AI coding agent rules (AGENTS.md, Cursor, Claude)

Setup instructions and rule files for AI coding agents: AGENTS.md, .cursorrules, CLAUDE.md, and hosted MCP configuration.

Read guide
Documentation

REST API Reference & Endpoints

Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.

Read guide
Documentation

Model Context Protocol (MCP) Server

Connect AI agents directly to SadaSend via Model Context Protocol (MCP). Inspect tools, configure execution scopes, and enable human approval holds.

Read guide
Deep Dive5 min read

Indirect Prompt Injection Defense in Email: Sanitizing Inbound Content for AI

Inbound emails processed by AI agents can contain hidden jailbreaks designed to hijack tools. Here is how to engineer a multi-layer prompt injection defense pipeline.

Read tutorial
Deep Dive3 min read

Indirect Prompt Injection via Email: Threat Models, Attack Vectors, and Prevention

When an AI agent reads incoming emails and holds a sending key, an attacker can embed invisible instructions. Here is how indirect prompt injection works and how to neutralize it.

Read tutorial
Deep Dive3 min read

How to Safely Let Agents Send Email: Defense-in-Depth for Autonomous Outbound

An engineering guide to defense-in-depth for autonomous email: preventing indirect prompt injection, infinite retry loops, and unverified recipient spam.

Read tutorial
Deep Dive5 min read

Preventing Infinite Email Loops in Autonomous AI Agents: Circuit Breakers and Token Buckets

When two autonomous email agents start talking to each other, they can trigger an infinite email loop in minutes. Here is how to engineer circuit breakers, token buckets, and idempotency safeguards.

Read tutorial
Deep Dive2 min read

Email Threat Modeling for SaaS: Preventing Compromised API Key Abuse

What happens when an engineer accidentally commits an email API key to a public GitHub repo? Here is the threat model and defense blueprint.

Read tutorial