uBumi

Legal

Trust and security

Last updated 8 September 2026. This is the early-access version. The full document will replace it before general availability, and we will notify every workspace owner when it does.

Approval by default

AI employees propose actions; they never execute them directly. Sending email, booking with outside attendees, publishing, and anything financial or destructive is held for a person unless your policy says otherwise. New workspaces start in shadow mode for two weeks, where every external action is held.

Untrusted content stays data

Email bodies, form submissions, and web pages are treated as data, never as instructions. A run that has read outside content is marked, and stricter policies apply to what it can do next. Outbound text passes a validator for banned phrases, unapproved prices, and links outside your allowlist.

Least privilege

Each connection asks for the narrowest permissions the job needs. Google access is limited to reading, labelling, drafting, and sending mail, and to calendar events. Tokens are encrypted at rest and revoked at the provider when you disconnect.

Audit

Every proposal, decision, approval, and execution is written to an append-only audit log per workspace, with who did what and when. You can read it on the Activity page.

Reporting a concern

Security questions or a suspected vulnerability: support@ubumiai.com. We reply to security reports first.