Security

How SteelGaze approaches service security and how to report a vulnerability.

Last updated: 27 July 2026

Security approach

SteelGaze uses encrypted network connections, provider-managed authentication and database controls, access restrictions, security headers, secrets management, and limited administrative access. Connected-inbox credentials and tokens are intended to be restricted to the services that require them.

Infrastructure providers

Service delivery depends on Contabo, Supabase, Cloudflare, Google, Resend, Purelymail, and Vercel Speed Insights. Their security and availability form part of the service's risk profile. No technical or organizational measure can guarantee that a service is invulnerable.

Your responsibilities

Use a unique password, protect authentication links and inbox credentials, disconnect integrations you no longer use, submit only content you are authorized to process, and independently verify high-impact decisions. SteelGaze analysis is a supporting signal, not a substitute for layered email security.

Report a vulnerability

Email [email protected] with a concise description, affected endpoint, reproduction steps, and impact. Do not access other users' data, disrupt production, use social engineering, or publish sensitive details before we have had a reasonable opportunity to investigate.

Incidents

We investigate credible security reports and will provide legally required notices when a confirmed incident affects personal data. Operational updates may also be posted on the status page.