Vannus / Catalog / SaneBox

SaneBox

This entry runs no foundation model. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

AI email management that prioritizes your inbox and filters noise across any email provider, processing message headers rather than full message contents

productivity, email, automation
Model provenance

No foundation model. SaneBox does not run one, so this criterion does not apply and is excluded from the grade rather than counted against it. Email triage by behavioural pattern matching rather than generative AI. The vendor's own security page describes the mechanism as analysing which messages you open, reply to, and how quickly. Reviewed from the vendor’s own documentation: sanebox.com ↗ If that is out of date, tell us at right of reply.

Who controls it
US corporate controlNot established — our catalogue recorded US control for this vendor, but we hold no document naming a US entity, so the claim is withdrawn until we do. This is a gap in our sourcing, not a finding about this vendor.
Trains on your dataYes, unless you opt out — on the vendor's default plan

Training and retention posture varies by plan. What we publish above describes the vendor’s default plan; enterprise, team and API agreements frequently differ, often materially, and a contract can override the published default entirely. Check your own plan and contract before relying on this row.

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Compliance the vendor states
GDPR

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit SaneBox ↗ Grade your whole stack →