Security

🛡️ Security at EmailConnect

We take security seriously. This page outlines our security practices and how to responsibly disclose vulnerabilities.

Responsible disclosure policy

We welcome security researchers to help us keep EmailConnect secure. If you discover a vulnerability, please report it responsibly following the guidelines below.

How to report a vulnerability

Send your report to:

security@emailconnect.eu

Please include as much detail as possible: steps to reproduce, potential impact, and any proof-of-concept code.

What to expect

TimelineOur commitment
Within 24 hoursWe acknowledge receipt of your report
Within 7 daysWe provide an initial assessment and severity evaluation
Within 90 daysWe aim to resolve confirmed vulnerabilities

Scope

The following systems are in scope for security testing:

  • emailconnect.eu — Marketing website
  • app.emailconnect.eu — Application platform

Out of scope

The following are explicitly excluded from testing:

  • Denial of Service (DoS/DDoS) attacks
  • Social engineering or phishing of employees or users
  • Physical security attacks
  • Attacks against third-party services we use
  • Automated vulnerability scanning without prior permission
  • Spam or email bombing
  • Any testing that could degrade service for other users

Safe harbor

If you follow this policy in good faith, we will not pursue legal action against you. We ask that you:

  • Do not access or modify data belonging to other users
  • Do not publicly disclose vulnerabilities before we've had a chance to fix them
  • Act in good faith to avoid privacy violations and service disruption
  • Only test against accounts you own or have explicit permission to test

Our security practices

🔐 Encryption

All data encrypted in transit (TLS 1.3) and at rest. No unencrypted connections accepted.

🇪🇺 EU infrastructure

100% European servers and operations. No exposure to foreign surveillance laws.

🔍 Access control

Principle of least privilege. All access logged and auditable. No shared credentials.

📋 Regular audits

Continuous dependency scanning. Regular security reviews of infrastructure and code.

Security headers

We implement industry-standard security headers including:

  • Content Security Policy (CSP)
  • X-Frame-Options to prevent clickjacking
  • X-Content-Type-Options to prevent MIME sniffing
  • Strict referrer policy
  • Permissions policy restricting unnecessary browser APIs

Related resources

Need enterprise-grade security controls?

Our enterprise tier adds immutable audit logging, role-based access control, IP whitelisting, signed DPAs, and SLA guarantees for organisations that need full compliance accountability.

Talk to us about enterprise

Questions about our security practices?

Contact us at security@emailconnect.eu