Security
How SteelGaze approaches service security and how to report a vulnerability.
Last updated: 27 July 2026
Security approach
SteelGaze uses encrypted network connections, provider-managed authentication and database controls, access restrictions, security headers, secrets management, and limited administrative access. Connected-inbox credentials and tokens are intended to be restricted to the services that require them.
Infrastructure providers
Service delivery depends on Contabo, Supabase, Cloudflare, Google, Resend, Purelymail, and Vercel Speed Insights. Their security and availability form part of the service's risk profile. No technical or organizational measure can guarantee that a service is invulnerable.
Your responsibilities
Use a unique password, protect authentication links and inbox credentials, disconnect integrations you no longer use, submit only content you are authorized to process, and independently verify high-impact decisions. SteelGaze analysis is a supporting signal, not a substitute for layered email security.
Report a vulnerability
Email [email protected] with a concise description, affected endpoint, reproduction steps, and impact. Do not access other users' data, disrupt production, use social engineering, or publish sensitive details before we have had a reasonable opportunity to investigate.
Incidents
We investigate credible security reports and will provide legally required notices when a confirmed incident affects personal data. Operational updates may also be posted on the status page.