Security program
Security and Responsible Disclosure
Effective and last updated: August 5, 2026
User protections
- One-way PBKDF2 password hashing; readable passwords are never stored.
- Authenticator-app MFA, single-use recovery codes and session revocation.
- Secure HttpOnly cookies, CSRF validation, same-origin enforcement and security headers.
- Rate limits, account lockouts, login alerts and security activity history.
- Encryption in transit and provider-supported encryption at rest.
- Mailbox quotas, attachment type/size controls, optional external malware scanner and quarantine.
- Role-based administration, immutable audit events and dual approval for exceptional mailbox-content access.
Responsible disclosure
Report vulnerabilities to [email protected]. Include the affected endpoint, reproduction steps, impact and a safe proof of concept. Do not access another person’s data, perform denial-of-service testing, send spam, deploy malware, social-engineer users or publicly disclose an unresolved issue.
Response process
JGAMail will acknowledge valid reports, triage severity, investigate, remediate and communicate status where practical. A report does not authorize activity prohibited by law. A safe-harbor commitment should be finalized by counsel before public launch.
Security limitations
No service can guarantee absolute security. Users should use a unique password, enable MFA, protect recovery codes, keep recovery contact information current and report unexpected activity immediately.