Why your keys and your mailbox stay yours
Connecting your email and your API keys to an agent is a real decision. What Istos stores, how it's locked, what it will never do with it, and why each account sends only with its own credentials.
To be useful, Istos needs a few things that matter: a way to send email as you, and sometimes keys to services you pay for, like an email finder or your X account. Handing those to any piece of software deserves a second thought. It should deserve more when the software is an agent.
This post is the plain version of how Istos treats them, and the rules I built it around. It's not a security certification. Istos doesn't claim one. It's what the product does today, and why.
What Istos holds for you
Depending on what you connect, your account may hold:
- Your own mailbox, over SMTP, for sending approved email from your address: the server, port, your address and the password or app password.
- Email finder keys, for Hunter, Prospeo or LeadMagic, if you use them.
- Keys for your own X app, if you post to X from the queue.
- An Instantly key, on Studio, if you send lead email through your own Instantly workspace.
Each is stored as its own entry under your account, and nothing else.
Locked before it's stored
Every one of those is encrypted before it reaches the database, with AES-256-GCM, a standard, strong form of encryption. What sits in the database is the locked version.
Once you've saved a key or a password, it never comes back out to the page. Your browser is told that a key is there and whether its last test worked. For a mailbox, it's told the server, the port and the address, never the password. The settings the app reads back are only the ones it's allowed to change, never a key, a password or your resume file. And keys are never written to logs.
That's also why you'll see Replace key rather than a field showing your old one. To change it, you paste a new one.
Your credentials, and only yours
This is the rule I care most about. In Istos, an account only ever sends with its own credentials.
That sounds obvious. It isn't how every tool works. A simpler design would have a shared mailbox or a shared sending account that steps in when yours isn't ready, so the product "just works". The cost is that email goes out under a name or from a server you didn't choose, and your outreach shares a reputation with strangers.
So Istos refuses that shortcut:
- No fallback. If your own mailbox isn't connected, your email doesn't go out through someone else's. The owner's own mailbox, used for Istos's system emails, is never used for any other account's outreach.
- No silent swap. If a draft is set to go out a particular way, Istos either sends it that way or refuses and tells you what to fix. It never switches to another route on its own.
- Only what you can use. Settings only offers the sending routes your account can actually use right now, and the server checks again when you save.
Checks on what you connect
A few more checks sit around the mailbox in particular:
- A real mail server. The server you enter has to be a public mail server, on the standard secure ports, 465 or 587. That keeps a typo, or something worse, from pointing Istos at somewhere that isn't a mailbox.
- Tested before it's trusted. Save and test checks the connection, so you find out straight away if a password or setting is wrong, not when your first approved email fails.
- Yours to remove. Remove your mailbox or a key at any time on Connections. Removing it deletes the stored copy.
What it's used for, and what it isn't
Your keys are used to act for you, on things you set in motion: sending an email you approved, looking up an address you asked for, posting an X post you approved. That's the whole list.
A few things Istos won't do, from its terms and privacy policy:
- It doesn't sell your data.
- It doesn't use your documents to train models.
- It keeps your data in managed databases in the European Union. Text sent to a model provider to write or score something is processed under that provider's data agreement.
- When you close your account, your data is deleted within 30 days.
And the rule over all of it: nothing sends without your approval. Keys make sending possible. They don't make it automatic.
Why this matters more for an agent
A normal app does what you click. An agent does things on its own, between your clicks: it reads job boards, scores leads, writes drafts. That's the point of it, and it's also why the edges have to be firm.
Istos's agents can find, check and draft as much as they like. What they can't do is reach outside your account: no one else's mailbox, no one else's keys, no sending without you. When those edges are fixed in the code rather than left to a setting, you don't have to wonder.
If you're setting things up now, how to connect Gmail and send from your own address covers connecting your own mailbox, and how to find verified email addresses with your own keys covers the finder keys.
Let the agents do the searching
Istos is in private beta. Join early access, or try the free preview on your resume, your website or your raise first. Nothing sends until you approve it.