Legal

Security & Disclosure

How we protect your data, and how to reach us if you find a vulnerability.

Effective: 2026-05-01 · Version: v1.0

Security

Last updated: 2026-05-27


Security is part of how we earn and keep our customers' trust. This page tells security researchers how to reach us, what we commit to in return, and what's out of bounds.


Responsible Disclosure: Our Promise

If you believe you've found a security vulnerability in our service, we want to hear from you. We commit to:

We take coordinated disclosure seriously and will work with you through the process.


How to Reach Us

Pick whichever channel you're most comfortable with.

Email (PGP-encrypted preferred)

[email protected]

PGP fingerprint: Available on request. Email [email protected] and we will reply with our current key fingerprint and public key over your preferred secure channel.

Plain email (for anyone who doesn't use PGP)

Plain email to [email protected] is fine. We understand not every researcher has PGP set up and we'd rather hear about issues in the clear than not at all.


What to Include in a Report

Help us help you:

If you want public credit, include the name/handle you want us to use. If you want to remain anonymous, say so and we'll respect it.


Safe Harbour

We welcome good-faith security research. If you:

then we will:

This safe harbour applies only to activity permitted by this policy. It does not extend to researchers acting in bad faith, attacking our customers' data, or causing deliberate damage.


Scope

In scope:

Out of scope:


AI-Specific Rules

Prompt injection testing is welcome but must be done carefully:

We're actively interested in novel prompt-injection classes, memory-poisoning patterns, and cross-tenant leakage paths.


What We Won't Offer (Today)


Our Own Security Posture

If you're researching us and want to understand our posture before engaging:

We publish our architecture and security thinking in the open because a service handling your email should be inspectable.


Hall of Fame

Security researchers who have made responsible disclosures to us:

(Empty at launch. We'd love for yours to be the first entry.)


Contact Summary

Purpose Address
Security vulnerabilities [email protected] · PGP preferred
Privacy concerns [email protected]
Abuse reports (spam from our service) [email protected]
Everything else [email protected]