Every incoming message is screened for prompt-injection before any reasoning, so an email cannot issue instructions to the AI. Verifying the wording matches what fully ships.