We welcome security research and treat good-faith reports as a contribution to the product. This page describes what we ask of researchers and what we commit to in return.
Last updated: April 2026.
Our primary public attack surfaces are:
Send your findings by email. We do not operate a bug-bounty platform; private email is the only reporting channel.
If you report a vulnerability to us in good faith and act reasonably — you do not exfiltrate user data beyond what is strictly necessary to demonstrate the issue, you do not disrupt the service, and you give us reasonable time to fix before public disclosure — we commit not to pursue legal action against you, and we will not ask your provider or hosting platform to do so either.
We do not operate a paid bug-bounty program at this stage. What we can offer: a credit on our public researchers page, a SmartEmails lifetime account, and fast-tracked enterprise contract negotiation for your employer if that is relevant. If a bounty program is something that would make a difference to you, tell us — we track demand.