Field 07 — Postage

You pay for comprehension. Never for safety.

Every tier runs the full trust boundary — clean, sanitize, and prompt-injection screen — on every message. The price is what your agent gets to understand, not how many inboxes you rent.

Four things a raw inbox hands your agent as-is — here they're the product

Injection screening

Flagged mail is delivered deterministic-only — never as trusted content. Fail-closed.

Sanitize + report

Hidden text, zero-width characters, and homoglyphs stripped. Every removal logged.

Schema extraction

Your JSON Schema in; typed fields and a confidence score out.

wait_for_email

Your agent blocks for the reply instead of polling the inbox.

Launch offer Early-stage team? Your first month of Scale is on us — just mention it when you reach out.

Free
$0/mo

Taste comprehension. No card.

100 comprehended messages / moschema extraction + injection scan — then unlimited sanitization
  • 3 mailboxes
  • 3,000 sends / month
  • Unlimited hidden-content sanitization
  • REST + MCP (hosted and local npx)
Start free
Most popular
Pro
$20/mo

For a developer shipping agents.

1,500 comprehended messages / moextracted to your JSON schema · classified · confidence-scored
  • Everything in Free
  • 10 mailboxes
  • 10,000 sends / month
  • Custom sending domains
  • Email support
Start Pro
Scale
$200/mo

For a team running agents in production.

25,000+ comprehended messages / mohigh-volume comprehension + extraction
  • Everything in Pro
  • 150 mailboxes
  • 150,000 sends / month
  • Multiple custom domains
  • Priority support + shared Slack
  • Annual billing available
Talk to us

Sanitization and prompt-injection screening run on every message, on every tier — safety is never metered. You pay for what your agent gets to understand.

Two guarantees behind it

30-day money-back

Go Pro risk-free. If Postfleet isn't comprehending your mail the way you need within 30 days, email us — full refund, no questions.

The injection guarantee

If a message we flag as a prompt-injection risk is ever delivered to your agent as trusted, comprehended content, that month is on us. The pipeline fails closed by design — this stands behind it.

Questions

What's a "comprehended message"?

An inbound message that runs the full LLM stage — a prompt-injection scan, then extraction to your JSON schema with a classification and a confidence score. Sanitization (stripping hidden text, zero-width characters, and homoglyphs) runs on every message and never counts against this.

What happens when I hit my comprehension limit?

Extraction pauses for the rest of the month — but deterministic sanitization keeps running on every message, so your agent still receives clean, screened text. Upgrade or wait for the monthly reset to turn extraction back on.

Is safety really free?

Yes. Hidden-content sanitization is deterministic — no LLM — so it runs unmetered on every message, on every tier, including Free. You only pay for comprehension (the LLM extraction), never for safety.

What does the injection guarantee cover?

If a message we flag as a prompt-injection risk is ever delivered to your agent as trusted, comprehended content, that month is on us. It covers our fail-closed gate holding — not a promise to catch every conceivable injection. Flagged mail is delivered deterministic-only by design.

Do you train models on my email?

No. Your mail is processed only to comprehend it for you, and our model provider does not train on API traffic.

Hosted or local (npx) — same pricing?

Same. The hosted MCP endpoint and npx @postfleet/mcp use the same pf_ key and draw from the same plan limits. Pick whichever fits your setup.

Can I cancel or change plans?

Cancel anytime from the dashboard. Pro is backed by a 30-day money-back guarantee, so you can try it risk-free.