Open Varcmail

Varcmail · varcmail.varcbytes.com

Security Policy

How to report security issues and use Varcmail safely.

Security practices

Varcmail uses password hashing, server-side sessions, access-controlled mailbox queries, validation, rate limiting, private object storage for attachments, encrypted SMTP credentials, and health monitoring. Security is continually reviewed, and this summary is not a guarantee that vulnerabilities cannot occur.

Responsible disclosure

If you believe you found a vulnerability, email support@varcbytes.com with the subject “Varcmail security report”. Describe the affected feature, reproduction steps, impact, and a safe way to contact you.

  • Do not access, modify, retain, or share another person’s data
  • Do not disrupt service, send spam, perform denial-of-service testing, or use destructive techniques
  • Use test accounts and the minimum testing necessary
  • Allow reasonable time to investigate before public disclosure

Account safety

Use a unique password, protect your device, sign out on shared devices, and notify your administrator promptly if you suspect compromise. Browser notifications may reveal that a new email arrived, but Varcmail avoids placing message content in the notification body.

Scope and response

This policy does not promise a reward or safe-harbour beyond rights provided by applicable law. We aim to acknowledge good-faith reports, assess severity, and communicate material remediation progress when practical.