Legal
Security & Vulnerability Policy
Our approach to protecting InboxDays and a clear channel for responsible vulnerability disclosure.
1. Security program overview
InboxDays is built as a trust-first email platform. We apply defense-in-depth across application, identity, and cloud infrastructure layers, aligned with common expectations for SOC 2 / ISO 27001-ready SaaS programs (controls mature over time; ask enterprise sales for current report availability).
2. Core controls
- TLS encryption in transit for web, API, and auth endpoints.
- Cloud hosting on AWS with least-privilege IAM, network isolation, and managed databases.
- OIDC/OAuth authentication via Keycloak with PKCE for public clients.
- Client-side AES-256-GCM for Vault / secure-link payloads where zero-knowledge features apply.
- Access logging and operational monitoring for production services.
- Subprocessor diligence as listed in the Subprocessor Directory.
3. Tamper-evident audit disclosures
Enterprise audit features may record security-relevant metadata (actor, action type, timestamp, target resource identifiers) to support accountability. Audit logs are designed to be append-oriented and protected against silent alteration. Audit trails capture metadata about actions, not decryption of zero-knowledge Vault ciphertext.
4. Customer responsibilities
- Protect account credentials and passkeys.
- Configure TTL / delete rules knowingly (see Terms auto-purge disclaimer).
- Safeguard Vault keys and secure-link fragments.
- Review AI drafts before sending.
5. Vulnerability disclosure
If you believe you have found a security vulnerability, email security@inboxdays.com with a detailed report (affected URL/API, reproduction steps, impact). Please give us a reasonable time to investigate before public disclosure. Do not access other customers’ data or destroy systems while testing.