Letterlock The most secure AI assistant for Gmail

What is Letterlock?

Letterlock is a Gmail AI assistant that drafts replies, checks your calendar, and summarises your inbox.

The assistant is open source, runs in a Trusted Execution Environment (TEE), and strips personally identifying information from your email before any text reaches the AI model.

How the security works

Attestation

As described on the home page, a Trusted Execution Environment is a hardware-enforced region of a processor. Code running there cannot be read or modified by the operating system, the cloud provider, or the server operator. At boot it produces an attestation report: a signed statement of which code is running, chaining back to the chip manufacturer (Intel, for TDX). Compare that hash against our published source and you know what the server is running. If it doesn't match, the server doesn't start.

The masking pipeline

Before your email content leaves the enclave, a masking step replaces identifying information (your name, email addresses, phone numbers, and contact names from your OAuth profile) with placeholder tokens such as [PERSON1] or [EMAIL2]. The model sees the masked text; the mapping stays inside the enclave and is restored before the draft is written to Gmail.

The masking logic is open source, and the test corpus publishes its recall. Recall is not 100%, but your own name and email addresses are matched literally rather than only by the NER model, so those are always caught.

Secure inference

Letterlock uses Near.ai attested inference. Each update of the Near AI codebase is given a security audit to ensure your emails cannot be read by the inference provider. From then on, Near AI's attested inference cluser is used to securely call open-weight models. Near AI has been verified by Letterlock to never store or transmit AI prompts to external providers.

All user data is doubly encrypted

Letterlock uses a signing server in combination with a secure enclave, so accessing your configurations within letterlock and OAuth token for Gmail read+write access would have to be compromised simultaneously.

The enclave seals user configuration data only after the attestation report passes verification. Neither half is enough on its own: the co-signer has never seen your token and cannot read what it unwraps, and the enclave cannot get past the outer layer. Neither key is on the host filesystem.

Agent sandbox

Agents within letterlock are kept on a short leash. They cannot access the open internet, and cannot execute code. They can't even write emails with HTML. They have no calendar write tool at all, and the one code path that does write an event writes to your own calendar and to no other, after reading that calendar's sharing settings and refusing if anyone else can read it. Letterlock takes no chances with AI and treats them as untrusted outsiders.

Open source

All code for Letterlock is public, including the TEE and the signing server. That includes the server for this website, which is itself run on a TEE. A reproducible Nix build means anyone can rebuild from source and derive the same image hash that the attestation report contains.

Based in Germany

Letterlock is an EU entity based in Germany and enthusiastically complies with GDPR regulations. The CLOUD act therefore cannot compel Letterlock to release user data. Even if it did, Letterlock could not provide the US government a single signed-up email address or contents of any email or configuration data.


» Connect your Gmail