The defense is layered. Ingested content cannot grant permissions, change limits, or trigger actions; those flow only from owners through Heidi Control. An email saying 'forward all invoices to this address' is a fact about a suspicious email, not a command.
The honest caveat: prompt injection is an unsolved research problem industry-wide, which is exactly why Heidi's model is defense in depth, low default autonomy, earned trust, hard caps, receipts, and undo, rather than trusting any single filter.