Pre-launch preview — not yet operational. Launching late 2026–2027.

AlecRae

Legal

Security & Responsible Disclosure

Effective Date: August 20, 2026 · Last Updated: August 20, 2026

Found something? Tell us.

Email [email protected]. We aim to acknowledge within 2 business days. Good-faith research is welcome and protected by the safe-harbour terms below.

1. What is in place today

AlecRae is in a pre-launch preview. This is the security posture as it stands, stated plainly; Section 2 lists what is planned and not yet done.

• Passwords are hashed with Argon2id. Passkeys (WebAuthn) are supported for sign-in.

• TLS on all web and API connections, with certificates issued by Let's Encrypt via our proxy.

• Stored credentials (OAuth tokens, DKIM signing keys) are encrypted at rest with AES-256-GCM using a server-held key.

• Nightly database backups are copied off-box, with a weekly automated restore test.

• Dependency audits and secret scanning run in CI on every change.

• Access to production systems is by passkey or SSH key. A formal access policy will be published before launch.

• Hosting: Vultr cloud servers in the United States (Chicago). No other hosting provider is used.

2. Planned, not yet in place

• End-to-end encryption of email content. Email is not end-to-end encrypted today.

• STARTTLS on inbound mail transport. Received mail currently transits without transport encryption on the last hop.

• Round-the-clock security monitoring and real-time alerting.

• Independent penetration testing and a paid bug bounty.

• SOC 2. AlecRae is not certified under SOC 2 or ISO 27001.

• Published recovery objectives (RPO/RTO), once measured.

3. Scope

The following assets are in scope for responsible disclosure:

• alecrae.com (marketing site and legal pages).

• mail.alecrae.com (web application).

• api.alecrae.com (public API).

Nothing else is in scope. There is no staging environment or admin subdomain to test against, and the mobile and desktop apps are not yet released.

4. Out of scope

• Denial-of-service and volumetric attacks.

• Social engineering of anyone working on AlecRae, or of users.

• Physical attacks.

• Issues that require a privileged network position.

• Third-party services we do not operate (Vultr, Vapron, Resend, Anthropic, Stripe, Cloudflare, GitHub).

• Missing best-practice headers without a demonstrated exploit.

• Self-XSS or clickjacking without security impact.

• Vulnerabilities in third-party libraries without a demonstrated exploit against AlecRae.

5. Safe harbour

AlecRae authorises security research conducted in accordance with this policy. We will not pursue civil or criminal action under the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), the UK Computer Misuse Act, or any equivalent law, provided you:

• Make a good-faith effort to avoid privacy violations, data destruction and service degradation.

• Only interact with accounts you own or have explicit permission to access.

• Do not exfiltrate data beyond the minimum needed to demonstrate impact.

• Give us a reasonable time to fix before public disclosure (target: 90 days).

• Do not extort, threaten, or demand payment.

6. Rewards

We do not run a paid bug bounty today. We will credit reporters, with their permission, when we publish a fix. A reward programme is planned and its terms will be published on this page if and when it opens.

7. Disclosure timeline

• We aim to acknowledge within 2 business days and to share a triage result within 5 business days.

• Fix targets: Critical 30 days, High 60 days, Medium / Low 90 days.

• Coordinated public disclosure upon remediation or, at latest, 90 days after acknowledgment unless mutually agreed otherwise.

8. Encrypted reporting

We do not yet publish a long-lived PGP key. If your report is sensitive, email [email protected] first and we will arrange an encrypted channel. Our /.well-known/security.txt carries the same contact details.