Application controls
- Scrypt password hashing and HTTP-only, same-site session cookies.
- Workspace-bound authorization with owner, admin, analyst, and viewer roles.
- Hashed scoped API keys and encrypted webhook signing secrets.
- HMAC-signed webhooks, private-network destination blocking, rate limits, bounded input, and XML entity rejection.
- Versioned database migrations, auditable background jobs, retry limits, and dead-letter status.
Data minimization
EmailAudit primarily evaluates public configuration. Stored private data is limited to accounts, workspace settings, monitoring history, uploaded reports, and integration material required for requested features.
Security testing boundary
Do not attempt to access, change, or disrupt other people’s accounts, data, domains, or systems. EmailAudit does not currently operate a public vulnerability-reward program or represent this page as authorization to test the service.
Operational maturity
The application includes secure defaults and automated release checks, but those controls are not a certification. Managed backup validation, production key rotation, independent vulnerability review, incident-response operations, and external uptime monitoring remain required before EmailAudit makes formal compliance or availability claims.