Trust & AI · updated 2026-08-18

Trust is verifiable, or it is marketing.

This page documents how m6l handles data, security, and AI. Where we can, we show receipts you can check yourself instead of promises you have to take on faith. m6l is the brand of M6L LLC, a Texas Series limited liability company.

The short version

This site collects almost nothing (see the Privacy Policy). No AI system processes visitor data today. Our email domain is locked against spoofing at the strictest settings. And when any of that changes, this page changes first.

How we use AI today

AI is a working partner inside m6l: we use it to design, build, test, and operate, which is part of how a small team delivers agency-grade work. Two rules govern it. First, AI does not process visitor or client data unless we have said so here and named the providers. Second, commitments come from humans: scope, prices, and promises are made by a person, in writing, every time.

What this site does and does not do

No cookies, no trackers, no analytics, no fingerprinting. Static pages served over HTTPS with strict security headers (HSTS, a locked-down content security policy, frame denial). AI crawlers are welcome guests: we publish llms.txt and llms-full.txt so machines get the same story humans do.

Email that cannot be faked

From day one, m6l.ai enforces the strictest mail authentication available: DMARC at p=reject (spoofed mail is refused, not quarantined), SPF with a hard fail, DKIM signing at 2048 bits, and MTA-STS in enforce mode so delivery to us requires verified TLS. In plain words: if an email claims to be from m6l.ai and is not, major mail providers will refuse it outright.

One channel rule

Official communications come only from this website, official m6l accounts, and email from the m6l.ai domain. Anything else is not us; see Disclosures. This is deliberate anti-phishing design: one rule your whole team can remember.

Client data, when there is client work

Engagement data is governed by the written agreement for that engagement. Our defaults: collect the minimum, keep client data in the client's own systems wherever possible, and hand back every credential and access at the end. You own your stuff; we just take care of it.

Verify it yourself

Do not take our word for any of this. Check the response headers on this page, run this domain through a security-headers or DMARC checker, query our DNS records (_dmarc.m6l.ai, _mta-sts.m6l.ai), and read security.txt. If you find something we got wrong, we want to know.

Report a concern

Security reports, privacy questions, or anything that looks off: [email protected]. A person reads it, and a person answers.

← Back to m6l