Security Posture & Vulnerability Disclosure
Last Updated: September 13, 2026 • Production Baseline
1. Security Architecture
Security and privacy are core architectural foundations of HandoffMail. We apply defense-in-depth principles across every layer of the application, data storage, and worker infrastructure.
2. Encryption at Rest and in Transit
- Data in Transit: All web traffic and API endpoints require TLS 1.3 encryption. External API calls to Google APIs, Stripe, and Neon use strictly validated SSL/TLS certificates.
- Mailbox Credential Encryption: Google OAuth refresh tokens and sensitive credentials are encrypted using AES-256-GCM authenticated encryption with cryptographically random initialization vectors (IVs). Keys are versioned and can be rotated atomically without downtime.
- Database Encryption: Database storage volumes are encrypted at rest using industry-standard AES-256 block ciphers.
3. Application Hardening & Tenancy Isolation
- Strict Multi-Tenant Isolation: Every database query and state mutation is strictly scoped to the authenticated workspace identity with server-side authorization enforcement.
- SSRF Prevention: Outbound webhook deliveries and link verifications pass through dedicated private IP filter guards preventing access to loopback (127.0.0.1), link-local, cloud metadata services (169.254.169.254), or internal RFC 1918 subnets.
- Prompt Injection Defense: All untrusted external inputs (inbound prospect replies, subject lines) are wrapped with defensive delimiters and boundary instructions before evaluation by LLMs.
- Audit Logging: Administrative actions, token updates, credential rotations, campaign approvals, and human takeovers are logged with immutable timestamps and actor IDs.
4. Vulnerability Disclosure Program
We welcome responsible security research. If you believe you have discovered a vulnerability in HandoffMail, please report it immediately to our security engineering team:
security@handoffmail.com
Safe Harbor Guidelines:
- Provide reasonable time for our team to investigate and remediate the issue before public disclosure.
- Do not access, modify, or destroy customer or prospect data.
- Do not perform denial-of-service (DoS) attacks or social engineering against our staff.
- We commit not to pursue legal action against researchers acting in good faith under these guidelines.