You can now report a security vulnerability in mailkube and know in advance what will happen to the report and to you. The security page carries the route, and the terms of service carry a written promise not to come after anyone who uses it in good faith.
Where this sits with the Cyber Resilience Act
mailkube publishes software as well as running a service, and Regulation (EU) 2024/2847 applies to software placed on the EU market. That covers the repositories we publish on GitHub.
Two dates matter. From 11 September 2026, Article 14 requires a manufacturer to report an actively exploited vulnerability, with 24 hours for the first warning. Meeting that depends on hearing about the vulnerability in the first place, which is what this route is for. The remaining obligations, covering conformity assessment and technical documentation, take effect on 11 December 2027, and that work is still in progress.
Where to report a security vulnerability
It depends on what you found.
The platform is the API, the SMTP relay, the dashboard and the website. Those go by email to the address on the security page.
The published software is the repositories on GitHub. Those go through GitHub’s private advisory flow on the repository in question, which keeps the report attached to the code it concerns and visible only to maintainers. Email works too if you would rather not use GitHub.
Both routes end at the same policy: every one of those repositories carries a SECURITY.md pointing
at it.
What the safe harbour covers
Research a vulnerability in good faith and mailkube will not bring a claim against you, and will not support one brought by anyone else.
Good faith means the ordinary things. Take only the data needed to show the problem is real. Leave the service running, and go no further into other people’s data than the flaw itself already exposes. Use what you find for the report and nothing else, and send it without a price attached to it.
The report itself is confidential. We disclose it only as far as investigating and fixing the issue requires, and we take no rights in what you send.
All of that sits in Section 17 of the terms of service, which makes it a contract term rather than a promise on a page.
What happens after you send it
Every report is acknowledged, then read by someone who can fix it. You are told what we found. If we conclude something is not a vulnerability, you get the reasoning instead of silence.
There is no published response clock. What is promised here is the answer itself, and a number on a page would not make it arrive sooner.
Where to go next
If you have something to report, the security page has the detail, including what is useful to put in a report and how credit works.