Security
Regulation (EU) 2024/2847, the Cyber Resilience Act, requires a manufacturer of software placed on the EU market to run a coordinated vulnerability disclosure policy. This page is mailkube’s. The regulation reaches the software mailkube publishes, and the hosted platform takes the same route rather than a separate one.
So if you have found a security problem in mailkube, this page tells you where to send it and what happens after you do.
What this covers
Two things, and they take different routes.
The mailkube platform. The API, the SMTP relay, the dashboard, the website, and everything that runs behind them.
The published software. The repositories we publish on GitHub.
They are open source, and each one carries its own SECURITY.md.
Reporting a vulnerability
For the platform, email security@mailkube.com.
For one of the published repositories, use GitHub’s private advisory flow on that repository (Security, then Advisories, then Report a vulnerability). It opens a report visible only to the maintainers, and it keeps the issue attached to the code it concerns. Email works too if you would rather not use GitHub.
Two places not to send it: a public issue, and the support form. Neither one is read as a security report.
Useful things to include, none of them mandatory:
- what the issue is and what an attacker gets out of it,
- how to reproduce it, ideally a minimal proof of concept,
- the affected version, endpoint or commit,
- anything you already know about a fix.
Reporting anonymously is fine. We would still like to be able to ask you a question, so a throwaway address is more useful than none.
What to expect
Every report is acknowledged, then read by someone who can fix it.
There is no published response time, and that is deliberate. What is promised here is the answer: we come back to you, tell you what we found, and tell you what we are doing about it. If we decide something is not a vulnerability, you get the reasoning instead of silence.
Where a fix ships, credit goes to the reporter who wants it and is withheld from the reporter who does not. Ask either way.
Safe harbour for good-faith research
Research a vulnerability in good faith and mailkube will not bring a claim against you, and will not support one brought by anyone else. Your report is confidential. We disclose it only as far as investigating and fixing the issue requires, and we take no rights in what you send.
Report privately, and give us a reasonable chance to fix the issue before you publish.
The binding version is Section 17 of the Terms of Service, which sets out the conditions in full and governs where the two differ.
Where we are on the Cyber Resilience Act
The repositories on GitHub are the software placed on the EU market, so they are what the regulation above applies to.
The route on this page is live now. The Article 14 reporting obligations apply from 11 September 2026 and cover notifying an actively exploited vulnerability in one of those products, and mailkube is ready for them. The remaining manufacturer obligations take effect on 11 December 2027, and that conformity work is still in progress.