How to report
Email security@mailinizer.com. The machine-readable version of this page lives at /.well-known/security.txt and lists a fallback address in case that mailbox is unreachable.
Please include, as far as you can:
- The affected host, endpoint, screen or app version.
- Steps to reproduce, or a proof of concept that only touches your own account.
- The impact as you understand it.
- How you would like to be credited, if at all.
Scope
- mailinizer.com and every page on it
- api.mailinizer.com — the production API the apps talk to
- The Mailinizer iOS and Android apps
Third-party services we rely on (mail providers, app stores, our hosting provider) have their own disclosure programmes; please report issues in their products to them directly.
Rules of engagement
- Access, modify or delete data that is not your own. Use your own test account.
- Run denial-of-service, spam or brute-force tests, or automated scanners at volume against production.
- Social-engineer our staff or physically attack our infrastructure.
- Publish details before we have confirmed a fix — we will agree a disclosure date with you.
What you can expect from us
We acknowledge reports, keep you informed while we investigate, and tell you when a fix has shipped. We do not run a paid bug-bounty programme. Researchers who follow this policy and act in good faith will not face legal action from Axenta GmbH for their research; we consider it authorised.
Related
What we do with your mail and how it is stored is described in the privacy policy; general questions go to support.