Trust Center

Current evidence, current limits, and the exact Gmail boundary.

Yuvin publishes what is implemented, what Gmail authority exists, how real effects are verified, and which external gates remain open.

Last updated 30 July 2026

Product status

Yuvin Consequence is a development preview entering bounded pilot qualification. Its governance kernel, console, task intake, Gmail connection flow, action controls, and source-readback contracts have internal evidence. This is not an independent security, accessibility, compliance, or production-safety certification.

Public demonstrations and ConsequenceBench results use controlled evaluation environments. They do not prove that every connector action or customer deployment is qualified.

Gmail connector status

The Yuvin Gmail Connector supports account connection, message observation, draft creation, separately governed draft sending, token refresh, disconnect, and exact Gmail source readback. OAuth authority is kept separate from business-action approval.

The Google OAuth application is being prepared for sensitive and restricted scope verification. Until Google approves the production configuration, it must not be represented as publicly verified. Pilot access is limited to specifically authorized accounts and deployments.

Gmail authority boundary

  • Read capability requests permission to retrieve task-relevant Gmail messages and settings.
  • Draft capability adds permission to manage Gmail drafts.
  • Send capability adds Google send permission, but a separate Yuvin approval and canonical action are still required.

OAuth tokens remain in the server-owned encrypted secret provider. They are not exposed to the browser, model, task receipt, or public connector descriptor.

Google data handling

Gmail data is processed only for a user-requested task, governed draft or send action, source verification, duplicate prevention, recovery, security, or support. Yuvin does not sell Google user data or use it for advertising.

Task-relevant Gmail content may be sent to the model provider configured for the deployment. The model never receives the Gmail OAuth token or direct connector authority. The deployment must use provider terms that prohibit advertising use and general-purpose model training from this data.

See the Privacy Policy for categories, retention, sharing, user controls, and the Google API Services User Data Policy Limited Use disclosure.

Execution integrity

A Gmail API acknowledgement is not called completion. Draft and send actions bind the account, deterministic message identity, recipients, content hash, approval, effect ownership, and expected source state.

Timeouts and lost responses reconcile through exact Gmail readback before another mutation. A sent message reaches successful canonical completion only after the source contains the expected message identity, content hash, and sent state.

Deployment and qualification

The runtime contract can be reused, but trust is workflow-specific. Each deployment must qualify its connector release, OAuth client, model provider, policy mapping, approval roles, source of truth, retention, recovery behavior, hosting topology, and operational ownership.

A successful repository gate or Google OAuth review does not replace customer acceptance, independent penetration testing, accessibility review, regulatory analysis, or production reliability evidence.

Security and vulnerability disclosure

Good-faith reports are welcome at ml@yuvinlab.com with the subject "Security disclosure". Include reproduction steps, the affected surface, and the observed impact. Do not access third-party data, disrupt systems, or exfiltrate information beyond what is required to demonstrate the issue.

There is no public bounty program at this time. We will acknowledge valid reports and coordinate a safer channel if sensitive evidence is needed.

External evidence still required

  • Google brand, sensitive scope, and restricted Gmail scope verification;
  • security assessment where Google's restricted-scope rules require one;
  • independent application and infrastructure security review;
  • deployment-specific reliability, recovery, and operations evidence;
  • named customer pilot acceptance for the intended workflow.

Yuvin trust resources

Questions about privacy, security, access, or deletion can be sent to ml@yuvinlab.com.