InfraInbox v0.1 is in development. The self-hosted release and the Cloud beta open on the same day. Get told when it ships

Security

If you found a vulnerability in InfraInbox, the apps, the push relay or this website, tell us privately first.

Report a vulnerability

Email [security email] with what you found, how to reproduce it, and the version you tested. A machine-readable security.txt will carry the same address.

  • We acknowledge a report within [N business days] and keep you updated until it is fixed.
  • We fix confirmed issues in supported releases, publish an advisory, and credit you unless you prefer otherwise.
  • Please don’t access other people’s data, degrade the service, or publish details before a fix is out.

A formal disclosure policy and supported-versions table will be published with v0.1.

How InfraInbox protects your data

  • Destination tokens and other secrets are encrypted at rest and never written to logs or error messages.
  • Push notifications to the apps are end-to-end encrypted. The push relay forwards ciphertext it can’t read.
  • Sign-in supports two-factor authentication with an authenticator app and one-time recovery codes.
  • InfraInbox receives and routes alerts. It never controls your infrastructure.

The self-hosting docs cover the details: Security and privacy.