Enterprise

Inboxer for teams that need security review, not a credit card field.

SSO, audit logs, a published sub-processor list, a dedicated SLA, and a compliance pack ready before your security team asks. Built for 50-seat deployments and up.

Custom pricing · 50+ seats · We reply within 1 business day

Security-review ready from day one

SOC 2 Type I planned (controls in build-out with Drata). ROPA, DPA, sub-processor list, incident response runbook - all live and versioned.

Transparent sub-processors

Every sub-processor, its region, and its transfer mechanism is published and kept current. Analytics events are hosted entirely on PostHog Cloud EU. See the full list at /privacy.

Founder access

Direct Slack Connect with the founder for the first 30 days. We treat the first 10 enterprise design partners as co-builders, not tickets.

What’s in the Enterprise tier

Identity & access

  • SAML / OIDC single sign-on (Okta, Azure AD, Google Workspace, JumpCloud) - available on Enterprise contract
  • SCIM 2.0 user provisioning + de-provisioning - available on Enterprise contract
  • Enforced MFA per tenant
  • Role-based access control (Owner / Admin / Member) with custom roles on request
  • Domain-verified sign-up (block consumer addresses)

Security & compliance

  • AES-256 at rest, TLS 1.2+ in transit, field-level encryption for OAuth tokens and transcripts
  • SOC 2 Type I planned (controls in build-out with Drata)
  • EU-hosted customer content · public DPA · ROPA and the full sub-processor list maintained at /privacy - the evidence rather than a compliance badge, because GDPR compliance is not a certificate anyone issues
  • Third-party penetration test - contractual deliverable for Enterprise, summary shared under NDA once completed
  • Customer-Managed Encryption Keys (CMEK) - roadmap, contact us for timeline

Audit & observability

  • Structured in-app audit log of every admin and AI action (entries are anonymised, not deleted, on account erasure to stay GDPR-compliant) - Live
  • CSV/JSON audit log export - Available by contract
  • Continuous SIEM streaming (Datadog, Splunk, Sumo, S3 sink) - Roadmap, contact us for timeline
  • Per-user activity dashboards
  • Optional data export endpoint (Article 20 right-to-portability)

Data residency & sub-processors

  • Customer content (messages, drafts, tasks, transcripts) hosted in the European Union (Ireland)
  • Analytics events hosted entirely on PostHog Cloud EU (all visitors)
  • Full sub-processor list, with regions and transfer mechanisms, at /privacy
  • Sub-processor change notifications 30 days in advance
  • OpenAI Zero Data Retention: application submitted, awaiting approval
  • Anthropic: API terms - customer content is not used for model training
  • BAA available for HIPAA-relevant deployments (on request)

Reliability & SLA

  • 99.9% uptime SLA available on Enterprise contracts (with service credits)
  • Recovery objectives agreed per contract. On the current backup configuration - daily snapshots, no Point-in-Time Recovery - worst-case data loss is 24 hours; a sub-hour RPO requires the Supabase PITR add-on, which we enable for contracts that need it.
  • Managed daily database backups through Supabase, with a 7-day retention window. Point-in-Time Recovery is not currently enabled, so restores are performed from the available daily recovery points.
  • Annual backup-restoration drill defined in the incident-response runbook - not yet performed; the dated report is shared under NDA once it is
  • Status page with subscribed-email incident notifications - roadmap, contact us for timeline

Support & onboarding

  • Dedicated Slack Connect or Teams shared channel
  • Named CSM for 100+ seat accounts
  • Onboarding playbook with the founder for the first 30 days
  • Custom training session for end users (live or recorded)
  • Priority email + chat support - 4h business-hour response

Enterprise vs Professional

If you’re running a smaller team, Professional at $49/month per workspace (up to 20 connected inboxes) already covers smart triage, AI drafts, and the task queue. Enterprise layers in the things you only need once IT and Legal are at the table.

Professional

Self-serve · $49/month · up to 20 inboxes

  • All product features (triage, drafts, tasks, pre-meeting briefs - Gmail)
  • Google Workspace + Microsoft 365 connectors
  • Email + in-app support
  • MFA, OAuth, sub-processor disclosure

Enterprise

Custom · 50+ seats

  • Everything in Professional, plus:
  • SSO (SAML/OIDC) + SCIM provisioning
  • Dedicated SLA, published sub-processors, structured audit log (CSV/JSON export available by contract)
  • Named CSM, Slack Connect, founder onboarding
  • MSA / DPA / BAA, compliance pack ready

Common procurement questions

What does Enterprise cost?+

Custom. Anchored around $30-50 per seat per month for typical 50-200 seat deployments, with discounts for annual commitment and volume. Final pricing reflects your security review depth, data residency, and support tier. We send a quote within 1 business day of the first call.

How long does procurement usually take?+

For organisations with an existing security review process: 2-4 weeks from first call to signed MSA. For organisations doing their first AI vendor review: 4-8 weeks. We move at your pace and have all the compliance artefacts ready before kick-off so security review isn't the long pole.

What's the minimum seat count?+

50 seats. Smaller teams are best served by the Professional plan at $49/month per workspace (up to 20 connected inboxes); Enterprise economics only pencil out at 50+.

Do you sign a DPA / BAA / NDA / MSA?+

Yes to all four. We have standard templates that pass most enterprise legal reviews; happy to redline yours. BAA is gated on a separate compliance review since not every Inboxer deployment processes PHI.

Can we deploy in our own AWS / Azure account?+

Not today. Inboxer runs as managed SaaS on Vercel + Supabase. Self-hosting and BYOC are on the 12-month roadmap for the right enterprise customers. Reach out - we'll be honest about timing.

How do you handle data deletion?+

In layers, because they have different mechanics. Access is disabled immediately on request. Customer data in Inboxer-controlled active systems is deleted no later than 30 calendar days after the deletion request (a grace period for export applies on contract end); Managed daily database backups through Supabase, encrypted and retained for 7 days. Deleted data disappears from backups once that window has passed. Per-user deletion is real-time via the admin console or DSAR endpoint for data held in Inboxer's own systems. Request content already sent to Anthropic or OpenAI expires per each provider's contractual retention configuration - neither offers a customer-triggered deletion API for content already processed, so we cannot promise on-demand erasure there; once OpenAI approves Zero Data Retention for our account (application submitted, see Data residency & sub-processors below), eligible request content is never stored at rest by the provider in the first place. Records we are required to keep by law (billing and tax records, for instance) are retained for the statutory period and processed for no other purpose. Deletion attestations cover the systems where Inboxer can initiate or verify deletion; we don't attest to what we can't verify.

Ready to talk?

Send us a one-liner about your team and we’ll reply within one business day with next steps. No forms, no demo wall.

Email sales@inboxer.so