Built to be trusted with the relationship
MLX operates on your network and writes in your name. That is a serious thing to hand a piece of software, so the limits on what it may do are part of the product rather than a setting inside it.
Last updated 25 July 2026
Three commitments that are not configurable
These are the commitments the product is built around. None of them can be switched off by a user, an administrator, or us.
- A human approves before anything sendsMLX drafts and proposes. Every message is written for review and requires your explicit approval before it leaves your account. Nothing sends autonomously, there is no unattended send mode, and no setting changes this. Approving a batch is still approval: you see each draft and the evidence behind it before you release it.
- Do-not-contact is a hard stopOnce a person or firm is marked do-not-contact, MLX will not draft to them, queue them, or send to them. It is enforced where the draft is assembled rather than at the moment of sending, so a normal send cannot override it and a bulk action cannot step around it. A do-not-contact request received by any channel is honored across every deal in the workspace.
- Network connections are informed consentConnecting an email, calendar or professional network source is a separate, explicit act. It is never bundled into onboarding or implied by signing in. Before you connect, you are shown what MLX will read and what it will not. You can review every connected source and revoke any of them at any time.
What MLX reads, and what it does not
MLX builds a relationship graph and a set of dated signals. It needs enough of your professional context to find a warm path, and nothing beyond that.
MLX reads:
- Message and calendar metadata from sources you connect: who corresponded with whom, when, and how often. This is what establishes that a relationship exists and how current it is.
- Professional profile and connection data from a network source you connect, used to resolve people to organizations and roles.
- The criteria, notes and drafts you create inside MLX.
- Publicly available and licensed information about target companies: filings, press, job postings, company websites and trade coverage.
MLX does not:
- Read the body content of personal correspondence unrelated to a deal in your workspace.
- Sell, rent, or share your data with other MLX members. Your criteria, your pipeline and your contacts are yours alone and are not visible to any other customer.
- Use your workspace content to build a product for a competitor.
- Contact anyone in your network on its own initiative.
Separation between your workspace and the network
MLX gets better as more members use it. That improvement comes from aggregate, de-identified patterns about which classes of signal precede a transaction, never from exposing one member’s workspace to another.
Your deal criteria, your target list, your drafts, your replies and your contacts are scoped to your workspace. No other customer can see them, query them, or discover that a given company appears in them. Aggregate model improvement never carries a company name, a person, or a workspace identifier out of the workspace it came from.
How data is stored and who can reach it
- Data is encrypted in transit using TLS, and encrypted at rest by the managed infrastructure and database providers MLX runs on.
- Access to production systems is limited to the small number of MLX personnel who need it to operate and support the service, and is granted on a least-privilege basis.
- Authentication is single sign-on only, through your Google or Microsoft identity. MLX does not create, store, or verify passwords.
- Access to connected sources uses scoped OAuth tokens issued by your provider. Revoking the connection in MLX or with your provider ends that access.
- Administrative access to customer data is logged.
Retention and deletion
You can disconnect a source at any time, which stops further reading from it immediately. You can ask us to delete your workspace and its contents, and we will do so within 30 days of a verified request, other than records we are required to keep for legal or accounting reasons.
A do-not-contact record is a deliberate exception. Where someone has asked not to be contacted, we retain the minimum needed to keep honoring that request, because deleting it would defeat its purpose.
Subprocessors and infrastructure
MLX runs on established cloud infrastructure and uses a small number of third-party providers for hosting, data storage, error monitoring, and the identity providers you sign in with. We use reputable vendors, limit what each one receives to what it needs, and require confidentiality and security obligations from them. A current list of subprocessors is available on request, and we will give advance notice of a material change to any member using MLX at the time.
Where our security program stands today
MLX does not currently hold a SOC 2, ISO 27001, or HIPAA attestation. We say so plainly rather than implying otherwise, and you will not find a compliance badge anywhere on this site. We are building toward a formal audit and will publish the report when there is one to publish.
The practices described on this page are what we do now: single sign-on only, least-privilege access to production, encryption in transit and at rest, scoped and revocable source connections, logged administrative access, and a defined deletion path. They are the controls a SOC 2 Type II examination would look at, described honestly and without the assurance a completed examination would provide.
Your responsibilities
MLX drafts outreach; you send it. You remain the sender of every message released from your account, and you are responsible for ensuring your outreach complies with the law that applies to you, including anti-spam and electronic marketing rules in the jurisdictions you are contacting. MLX gives you the tools to honor a do-not-contact request. Acting on the substance of a reply is your call.
Reporting a security issue
If you believe you have found a vulnerability, write to security@mlxresearch.com with enough detail to reproduce it. We will acknowledge a report within two business days and keep you updated until it is resolved. Please give us a reasonable opportunity to fix an issue before disclosing it publicly. We will not pursue or support legal action against researchers who report in good faith and who do not access, modify, or delete other people’s data while testing.