Security

Security controls designed for real email operations.

Email carries account access, customer conversations, and sensitive business context. Super Mail Hub applies layered controls across the dashboard, API, mailboxes, and delivery pipeline.

Secure email routing and delivery controls

Account and tenant isolation

Session-based access and organization-scoped queries keep each workspace separated. Administrative operations use a distinct authorization boundary.

  • Strong password requirements
  • Secure, HTTP-only production sessions
  • Organization-scoped data access
  • Restricted platform administration

Safer sending credentials

Applications use scoped API keys instead of mailbox passwords. Full secrets are shown only at creation and stored as non-reversible hashes.

  • Dedicated keys per application or environment
  • Explicit mail.send scope
  • Immediate key revocation
  • Hourly, daily, and monthly quota enforcement

Mailbox and message protection

Inbound mail is evaluated before it reaches the inbox, while mailbox owners retain practical controls for suspicious senders.

  • Spam and phishing scoring
  • ClamAV attachment scanning
  • Sender allow and block rules
  • Automatic Spam and Trash retention

Responsible incident reporting

Please report suspected vulnerabilities privately through the security topic on our contact form. Include the affected URL and reproduction details, but never include passwords, API keys, or customer message content.

  • Private security contact route
  • Abuse and reputation review tools
  • Customer suppression controls
  • Auditable payment-event handling