Security
🛡️ Security at EmailConnect
We take security seriously. This page outlines our security practices and how to responsibly disclose vulnerabilities.
Responsible disclosure policy
We welcome security researchers to help us keep EmailConnect secure. If you discover a vulnerability, please report it responsibly following the guidelines below.
How to report a vulnerability
Send your report to:
security@emailconnect.euPlease include as much detail as possible: steps to reproduce, potential impact, and any proof-of-concept code.
What to expect
| Timeline | Our commitment |
|---|---|
| Within 24 hours | We acknowledge receipt of your report |
| Within 7 days | We provide an initial assessment and severity evaluation |
| Within 90 days | We aim to resolve confirmed vulnerabilities |
Scope
The following systems are in scope for security testing:
emailconnect.eu— Marketing websiteapp.emailconnect.eu— Application platform
Out of scope
The following are explicitly excluded from testing:
- Denial of Service (DoS/DDoS) attacks
- Social engineering or phishing of employees or users
- Physical security attacks
- Attacks against third-party services we use
- Automated vulnerability scanning without prior permission
- Spam or email bombing
- Any testing that could degrade service for other users
Safe harbor
If you follow this policy in good faith, we will not pursue legal action against you. We ask that you:
- Do not access or modify data belonging to other users
- Do not publicly disclose vulnerabilities before we've had a chance to fix them
- Act in good faith to avoid privacy violations and service disruption
- Only test against accounts you own or have explicit permission to test
Our security practices
🔐 Encryption
All data encrypted in transit (TLS 1.3) and at rest. No unencrypted connections accepted.
🇪🇺 EU infrastructure
100% European servers and operations. No exposure to foreign surveillance laws.
🔍 Access control
Principle of least privilege. All access logged and auditable. No shared credentials.
📋 Regular audits
Continuous dependency scanning. Regular security reviews of infrastructure and code.
Security headers
We implement industry-standard security headers including:
- Content Security Policy (CSP)
- X-Frame-Options to prevent clickjacking
- X-Content-Type-Options to prevent MIME sniffing
- Strict referrer policy
- Permissions policy restricting unnecessary browser APIs
Related resources
Need enterprise-grade security controls?
Our enterprise tier adds immutable audit logging, role-based access control, IP whitelisting, signed DPAs, and SLA guarantees for organisations that need full compliance accountability.
Talk to us about enterpriseQuestions about our security practices?
Contact us at security@emailconnect.eu