Security
This page explains what CatMail protects today, how to report a vulnerability, and where the limits are. We would rather be precise than impressive.
Report a vulnerability
Send reports to security@catmail.ltd. Please include the affected URL, steps to reproduce, expected impact, and a safe proof of concept. We do not have a paid bounty program yet, but we welcome coordinated disclosure.
Do not access other people’s mail, exfiltrate data, run destructive tests, or degrade service availability. If a proof needs real account data, use an account you control.
HTTPS with HSTS, secure cookies, same-origin forms, and no third-party analytics.
TLS on public mail endpoints, SPF/DKIM/DMARC for catmail.ltd, and TLS reporting records.
Password hashes use bcrypt; TOTP is available; recovery and backup codes are stored as hashes.
Remote images are blocked or proxied, and support tools are built for metadata-only investigation.