Trust
Security you can inspect, not just read about
Mail is sensitive by nature. Our security model is built on owner-scoped database access, encrypted transport, scoped credentials and short retention — with audit trails you can read.
- HTTPS everywhereSite and API served over TLS
- Owner-scoped accessRow-level security on every table
- Guest inboxes expireSigned-out inboxes last 2 hours
- Sandboxed HTML mailRendered in a restricted iframe
- Built for educationCoursework and QA workflows
- No card requiredCreate an inbox without payment
Row-level security
Every table is owner-scoped. A request can only ever read rows belonging to its own account.
Scoped API keys
Keys are hashed at rest, carry explicit scopes, support rotation, expiry and revocation.
Attachment scanning
Attachments carry a scan status, and files stay in private storage behind signed URLs.
Audit logs
Key lifecycle events, admin actions and API requests are recorded and queryable.
Data minimisation is the default
Mailboxes can expire. Attachments live in private buckets. We don't run ads, we don't insert tracking pixels into your mail, and we don't build advertising profiles from message contents.
Domain authentication
For custom domains we monitor MX, SPF, DKIM and DMARC continuously and surface the current status in the dashboard, so a broken record shows up before deliverability does.
Reporting a vulnerability
If you believe you've found a security issue, contact us before disclosing it publicly. We'll confirm receipt, keep you updated while we investigate, and credit you if you'd like.
Frequently asked questions
Ready to try InstantEduMail?
Create a mailbox in seconds — no card required — or subscribe for monthly notes on education email.
Create a free inbox