Legal & Governance

Security

How SteelGaze approaches service security and how to report a vulnerability.

Last updated: 20 August 2026

Security approach

SteelGaze uses encrypted network connections, provider-managed authentication and database controls, access restrictions, security headers, secrets management, and limited administrative access. Connected-inbox and notification credentials are restricted to server-side services. Slack webhook credentials are encrypted with Google Cloud KMS; notification queues and tables are unavailable to browser roles.

Notification safeguards

Notifications are opt-in and the database runtime starts disabled. OAuth and bot-link tokens are short-lived and single-use, internal and Telegram endpoints require dedicated secrets, and provider requests use fixed HTTPS domains with redirects disabled. Delivery history stores only normalized status details and safe failure codes for 90 days; it does not store provider response bodies, message bodies, raw headers, attachments, or suspicious URLs.

Infrastructure providers

Service delivery depends on Contabo, Supabase, Cloudflare, Google, Resend, Slack, Telegram, Mozilla, Apple, and Purelymail as applicable to the features you choose. Their security and availability form part of the service's risk profile. No technical or organizational measure can guarantee that a service is invulnerable.

Your responsibilities

Use a unique password, protect authentication links and inbox credentials, disconnect integrations you no longer use, submit only content you are authorized to process, and independently verify high-impact decisions. SteelGaze analysis is a supporting signal, not a substitute for layered email security.

Report a vulnerability

Email security@steelgaze.app with a concise description, affected endpoint, reproduction steps, and impact. Do not access other users' data, disrupt production, use social engineering, or publish sensitive details before we have had a reasonable opportunity to investigate.

Incidents

We investigate credible security reports and will provide legally required notices when a confirmed incident affects personal data. Operational updates may also be posted on the status page.