Security

We take the security of QaviMail seriously. If you believe you've found a vulnerability, please report it privately before public disclosure.

How to report

Our commitments

Scope

In scope: qavimail.eu.cc and its subdomains. Out of scope: rate-limiting reports without impact, self-XSS, and issues in third-party services (Supabase, Cloudflare, Paddle) — please report those upstream.

Hall of thanks

Researchers who have helped improve QaviMail will be listed here. Be the first — we welcome reports.