Varcmail · varcmail.varcbytes.com
Security Policy
How to report security issues and use Varcmail safely.
Security practices
Varcmail uses password hashing, server-side sessions, access-controlled mailbox queries, validation, rate limiting, private object storage for attachments, encrypted SMTP credentials, and health monitoring. Security is continually reviewed, and this summary is not a guarantee that vulnerabilities cannot occur.
Responsible disclosure
If you believe you found a vulnerability, email support@varcbytes.com with the subject “Varcmail security report”. Describe the affected feature, reproduction steps, impact, and a safe way to contact you.
- Do not access, modify, retain, or share another person’s data
- Do not disrupt service, send spam, perform denial-of-service testing, or use destructive techniques
- Use test accounts and the minimum testing necessary
- Allow reasonable time to investigate before public disclosure
Account safety
Use a unique password, protect your device, sign out on shared devices, and notify your administrator promptly if you suspect compromise. Browser notifications may reveal that a new email arrived, but Varcmail avoids placing message content in the notification body.
Scope and response
This policy does not promise a reward or safe-harbour beyond rights provided by applicable law. We aim to acknowledge good-faith reports, assess severity, and communicate material remediation progress when practical.