Draft — to be reviewed by counsel before publication
Vulnerability disclosure
Report a security issue in this service to security@sendtier.com. Counsel reviews this policy before it is public. The fields to publish in security.txt are in docs/security/security-txt.md.
Owner action: verify that security@sendtier.com receives mail before launch. This policy does not prove the mailbox is monitored.
How to report
Email security@sendtier.com. Include:
- The host you tested. Production hosts are to confirm.
- The URL or API path, and the time in UTC.
- What you observed, in enough detail for us to reproduce it.
- Your contact address if it is not the sending address.
Do not include message bodies, recipient lists, or other people's personal data in the report. Refer to a tenant by its tn_ id. Do not include a live API key. If a key was exposed, say so. An owner can revoke a key with a full-scope key. There is no unauthenticated revoke route. Write to security@sendtier.com with the key id (key_ prefix) and we will revoke the row.
Scope
In scope when the hosts exist:
- The HTTP API (
GET /health,/emails,/domains,/webhooks,/suppressions, and the dashboard organization routes, including export and deletion). - The marketing site and the dashboard.
- The ingest endpoint
POST /sns/ses-events. Do not send forged provider traffic to production. Tell us the weakness instead.
Out of scope:
- A third-party service we do not operate, including the email provider, the billing provider, and the site host. Report those vendors to them.
- Social engineering of people, physical access, and volumetric denial of service.
- Findings in a design mock or a docs draft that is not served to customers.
- The API returns HTTP 429 when an API key or a dashboard user exceeds the request rate, when a tenant exceeds a plan send cap, and when an organization export is repeated inside ten minutes. See the rate limits guide. Account signup is implemented. A report that only restates a published limit will be closed. A working abuse of a limit still belongs in a report.
The production host names are to confirm. Do not treat an example host in the spec as in scope.
Rules for research
- Use your own tenant. Do not access another tenant's data. Stop if a response contains another tenant's data, and report that.
- Do not change or delete data you do not own. Do not send mail to anyone who has not agreed to the test.
- Do not use a
st_live_key against recipients who are not you. - Give us time to fix the issue before you publish it. The draft window is 90 days from the day we acknowledge the report. To confirm by counsel.
What we will do
We will acknowledge the report. A target time for the acknowledgement is to confirm by counsel. We will investigate and, when we confirm the issue, we will work on a fix. We will credit you if you want credit and counsel agrees. We do not run a paid bounty. Do not state a reward.
Safe harbor, draft, to confirm by counsel: we will not bring a claim against you for research that followed this policy, stayed in scope, and avoided harm to other customers. This sentence does not bind a court until counsel publishes it. It does not cover access to other tenants, extortion, or destruction of data.
Production contact file
Publish Contact and Expires. RFC 9116 requires both. Also publish Preferred-Languages, Canonical, and Policy, as docs/security/security-txt.md describes. The site serves this page at /security/. Policy points there.