Security
We take the security of QaviMail seriously. If you believe you've found a vulnerability, please report it privately before public disclosure.
How to report
- Email security@qavimail.eu.cc.
- Include reproduction steps, affected URLs, and impact.
- Do not attempt to access other users' data or degrade service.
Our commitments
- Acknowledge within 3 business days.
- Provide a triage decision within 10 business days.
- Credit reporters (with permission) in the section below.
Scope
In scope: qavimail.eu.cc and its subdomains. Out of scope: rate-limiting reports without impact, self-XSS, and issues in third-party services (Supabase, Cloudflare, Paddle) — please report those upstream.
Hall of thanks
Researchers who have helped improve QaviMail will be listed here. Be the first — we welcome reports.