Field 07 — Postage
Every tier runs the full trust boundary — clean, sanitize, and prompt-injection screen — on every message. The price is what your agent gets to understand, not how many inboxes you rent.
Four things a raw inbox hands your agent as-is — here they're the product
Flagged mail is delivered deterministic-only — never as trusted content. Fail-closed.
Hidden text, zero-width characters, and homoglyphs stripped. Every removal logged.
Your JSON Schema in; typed fields and a confidence score out.
Your agent blocks for the reply instead of polling the inbox.
Launch offer Early-stage team? Your first month of Scale is on us — just mention it when you reach out.
Taste comprehension. No card.
For a developer shipping agents.
For a team running agents in production.
Sanitization and prompt-injection screening run on every message, on every tier — safety is never metered. You pay for what your agent gets to understand.
Two guarantees behind it
Go Pro risk-free. If Postfleet isn't comprehending your mail the way you need within 30 days, email us — full refund, no questions.
If a message we flag as a prompt-injection risk is ever delivered to your agent as trusted, comprehended content, that month is on us. The pipeline fails closed by design — this stands behind it.
Questions
An inbound message that runs the full LLM stage — a prompt-injection scan, then extraction to your JSON schema with a classification and a confidence score. Sanitization (stripping hidden text, zero-width characters, and homoglyphs) runs on every message and never counts against this.
Extraction pauses for the rest of the month — but deterministic sanitization keeps running on every message, so your agent still receives clean, screened text. Upgrade or wait for the monthly reset to turn extraction back on.
Yes. Hidden-content sanitization is deterministic — no LLM — so it runs unmetered on every message, on every tier, including Free. You only pay for comprehension (the LLM extraction), never for safety.
If a message we flag as a prompt-injection risk is ever delivered to your agent as trusted, comprehended content, that month is on us. It covers our fail-closed gate holding — not a promise to catch every conceivable injection. Flagged mail is delivered deterministic-only by design.
No. Your mail is processed only to comprehend it for you, and our model provider does not train on API traffic.
Same. The hosted MCP endpoint and npx @postfleet/mcp use the same pf_ key and draw from the same plan limits. Pick whichever fits your setup.
Cancel anytime from the dashboard. Pro is backed by a 30-day money-back guarantee, so you can try it risk-free.