跳转到内容

站内搜索

输入以搜索页面、文章和文档

Security & governance

Nothing goes out that a named person has not signed off.

PathWolf keeps the two decisions where automated outbound most often causes deliverability and reputational harm — targeting and messaging — under explicit human approval. Consent, suppression and anti-spam constraints are enforced and logged for every contact.

Human control

Humans govern; AI operates.

Before any campaign activates, an accountable human approves four decisions in particular. AI colleagues may not act outside them.

Approval before activation

An accountable human approves the target account list, the messaging templates and tone, the sending domains, and the outreach-compliance rules before a single sequence starts.

Bounded execution

The orchestrator holds the approved configuration as the binding parameter set. AI colleagues cannot exceed those bounds, add accounts or contacts that fail the agreed criteria, or send outreach outside approved parameters.

Escalation, not improvisation

The human sets escalation thresholds and reviews flagged or sensitive replies. Any action outside parameters, and any threshold breach, pauses the operation and escalates rather than proceeding.

Immutable compliance rules

Compliance rules are immutable to AI and changeable only by the accountable human. AI colleagues may not alter them without human sign-off.

Compliance and deliverability, owned by the operator.

Unmanaged automation damages the sender and the brand, and the Google and Yahoo sender rules introduced in February 2024 raised the bar for anyone sending at volume. PathWolf treats deliverability and compliance as work the operator owns, not a burden offloaded to the buyer.

Per-contact compliance

Every contact is processed against consent, suppression and anti-spam constraints — including CAN-SPAM, GDPR legitimate-interest and CASL — with the basis and approval recorded.

This produces an auditable per-contact record of who was contacted, on what basis, and under which approvals.

A persistent compliance-and-audit service sits beneath every action and writes an immutable activity log.

Deliverability controls

SPF, DKIM and DMARC authentication is applied to sending.

One-click unsubscribe is provided on outreach.

Spam-complaint monitoring runs against the under-0.3% threshold set by the Google and Yahoo February 2024 rules.

Access and integrations

Integrations to the customer's CRM and sending infrastructure operate under least-privilege, approved-scope access, read and write only within those scopes.

Any action outside approved parameters is blocked and escalated rather than executed.

PathWolf is built and domiciled in the DIFC, Dubai, as a venture of Future Thesis Lab; the DIFC-regulated structure provides the governance and accountability framework required before adopting agentic outbound.

Questions

What buyers ask before adopting governed outbound.

Who decides which accounts get contacted and what they receive?

A named, accountable human does. The target account list, the messaging templates and tone, the sending domains and the compliance rules are all approved before any campaign activates. AI colleagues discover, research, draft and run sequences within those approved bounds — they do not set them.

How do you protect our domain reputation under the newer sender rules?

SPF, DKIM and DMARC authentication is applied, one-click unsubscribe is provided, and spam complaints are monitored against the under-0.3% threshold set by the Google and Yahoo February 2024 rules. These controls are owned by the operator rather than left to the buyer.

Can the AI change compliance rules or contact people outside the agreed criteria?

No. Compliance rules are immutable to AI and changeable only by the accountable human. AI colleagues may not add accounts or contacts that fail the agreed criteria, and may not send outreach outside approved parameters. Threshold breaches pause the operation and escalate.

What record do we have of who was contacted and why?

Every contact is processed against consent, suppression and anti-spam constraints — including CAN-SPAM, GDPR legitimate-interest and CASL — with the basis and approval recorded. This creates an auditable per-contact record, backed by an immutable activity log written beneath every action.

What access do you take to our systems?

CRM and sending-infrastructure integrations operate under least-privilege, approved-scope access, with read and write confined to those scopes. Any action outside approved parameters is blocked and escalated rather than executed.

Do you hold formal certifications?

PathWolf is built and domiciled in the DIFC, Dubai, as a venture of Future Thesis Lab, and the DIFC-regulated structure provides its governance and accountability framework. We do not claim security certifications we have not completed; where you need specifics for procurement, contact us and a named person will respond.

Have a security or compliance question?

Tell us how your outbound is governed today and what your procurement team needs to see. A named person owns the response.