Skip to content

Trust

Security you can inspect, not just read about

Mail is sensitive by nature. Our security model is built on owner-scoped database access, encrypted transport, scoped credentials and short retention — with audit trails you can read.

  • HTTPS everywhereSite and API served over TLS
  • Owner-scoped accessRow-level security on every table
  • Guest inboxes expireSigned-out inboxes last 2 hours
  • Sandboxed HTML mailRendered in a restricted iframe
  • Built for educationCoursework and QA workflows
  • No card requiredCreate an inbox without payment

Row-level security

Every table is owner-scoped. A request can only ever read rows belonging to its own account.

Scoped API keys

Keys are hashed at rest, carry explicit scopes, support rotation, expiry and revocation.

Attachment scanning

Attachments carry a scan status, and files stay in private storage behind signed URLs.

Audit logs

Key lifecycle events, admin actions and API requests are recorded and queryable.

Data minimisation is the default

Mailboxes can expire. Attachments live in private buckets. We don't run ads, we don't insert tracking pixels into your mail, and we don't build advertising profiles from message contents.

Domain authentication

For custom domains we monitor MX, SPF, DKIM and DMARC continuously and surface the current status in the dashboard, so a broken record shows up before deliverability does.

Reporting a vulnerability

If you believe you've found a security issue, contact us before disclosing it publicly. We'll confirm receipt, keep you updated while we investigate, and credit you if you'd like.

Frequently asked questions

Ready to try InstantEduMail?

Create a mailbox in seconds — no card required — or subscribe for monthly notes on education email.

Create a free inbox