Security
If you found a vulnerability in InfraInbox, the apps, the push relay or this website, tell us privately first.
Report a vulnerability
Email [security email] with what you found, how to reproduce it, and the version you tested. A machine-readable security.txt will carry the same address.
- We acknowledge a report within [N business days] and keep you updated until it is fixed.
- We fix confirmed issues in supported releases, publish an advisory, and credit you unless you prefer otherwise.
- Please don’t access other people’s data, degrade the service, or publish details before a fix is out.
A formal disclosure policy and supported-versions table will be published with v0.1.
How InfraInbox protects your data
- Destination tokens and other secrets are encrypted at rest and never written to logs or error messages.
- Push notifications to the apps are end-to-end encrypted. The push relay forwards ciphertext it can’t read.
- Sign-in supports two-factor authentication with an authenticator app and one-time recovery codes.
- InfraInbox receives and routes alerts. It never controls your infrastructure.
The self-hosting docs cover the details: Security and privacy.