Security approach
SteelGaze uses encrypted network connections, provider-managed authentication and database controls, access restrictions, security headers, secrets management, and limited administrative access. Connected-inbox and notification credentials are restricted to server-side services. Slack webhook credentials are encrypted with Google Cloud KMS; notification queues and tables are unavailable to browser roles.
Notification safeguards
Notifications are opt-in and the database runtime starts disabled. OAuth and bot-link tokens are short-lived and single-use, internal and Telegram endpoints require dedicated secrets, and provider requests use fixed HTTPS domains with redirects disabled. Delivery history stores only normalized status details and safe failure codes for 90 days; it does not store provider response bodies, message bodies, raw headers, attachments, or suspicious URLs.
Infrastructure providers
Service delivery depends on Contabo, Supabase, Cloudflare, Google, Resend, Slack, Telegram, Mozilla, Apple, and Purelymail as applicable to the features you choose. Their security and availability form part of the service's risk profile. No technical or organizational measure can guarantee that a service is invulnerable.
Your responsibilities
Use a unique password, protect authentication links and inbox credentials, disconnect integrations you no longer use, submit only content you are authorized to process, and independently verify high-impact decisions. SteelGaze analysis is a supporting signal, not a substitute for layered email security.
Report a vulnerability
Email security@steelgaze.app with a concise description, affected endpoint, reproduction steps, and impact. Do not access other users' data, disrupt production, use social engineering, or publish sensitive details before we have had a reasonable opportunity to investigate.
Incidents
We investigate credible security reports and will provide legally required notices when a confirmed incident affects personal data. Operational updates may also be posted on the status page.