Skip to content
Security

Security & Responsible Disclosure

Last updated · June 24, 2026 · security@inboxlee.com

1. Reporting a vulnerability

Email security@inboxlee.com with the details. Please do not open a public issue or post the finding anywhere until we have had a chance to fix it. We acknowledge every report within 3 business days and keep you updated as we work it.

2. Scope

In scope: inboxlee.com, app.inboxlee.com, and the InboxLee API. Findings that affect the confidentiality, integrity, or availability of customer data or mailbox infrastructure are the highest priority.

3. Safe harbor

We will not pursue legal action against researchers who act in good faith and within this policy. Good faith means: only test accounts and data you own, never access or modify another user's data, do not degrade or disrupt the service, and give us reasonable time to remediate before any public disclosure.

4. What to include

A clear description of the issue, the affected URL or endpoint and parameters, step-by-step instructions to reproduce, the impact you believe it has, and any proof-of-concept. The more reproducible the report, the faster we can confirm and fix it.

5. Out of scope

Volumetric denial-of-service, social engineering or phishing of our staff or customers, spam or email spoofing of arbitrary third-party domains, automated scanner output without a demonstrated impact, and missing best-practice headers or configuration with no working exploit.

6. Our commitment

We acknowledge within 3 business days, work the fix on a severity-driven timeline, and keep you posted. We do not currently run a paid bounty, but we are glad to credit you publicly once the issue is resolved, if you would like that.

7. Contact

Security reports: security@inboxlee.com. The machine-readable version of this policy lives at /.well-known/security.txt.

Found something? Email security@inboxlee.com, we acknowledge within 3 business days.