Security
NeedEmail.com Security Contact
Last updated: July 23, 2026
Report Security Issues
Send vulnerability reports to security@needemail.com. For encrypted disclosure, include your PGP key and we will respond with our preferred secure channel.
What To Include
Include a clear impact summary, affected URL or endpoint, reproduction steps, proof of concept, timestamps, and your contact details. Avoid sending sensitive customer data unless strictly required.
Scope
In scope: NeedEmail.com web properties, authentication flows, API endpoints, and mail service control plane behavior. Out of scope: social engineering, denial of service, physical attacks, and issues in third-party services outside our control.
Disclosure Expectations
We support coordinated disclosure. Please give us reasonable time to investigate and patch before public disclosure. We will acknowledge good-faith reports and provide status updates when possible.
Machine-Readable Security Contact
A machine-readable policy is published at /.well-known/security.txt.