Skip to main content
Security

Vulnerability Disclosure Policy

We welcome responsible disclosure from security researchers who help keep Freightbox users and their inbox data safe.

Safe harbor

If you act in good faith, avoid privacy violations, avoid service disruption, and report findings promptly, we will work with you to validate and resolve the issue.

In scope

  • https://app.getfreightbox.com
  • https://api.getfreightbox.com
  • Freightbox-owned webhooks, OAuth flows, and mailbox integrations

Out of scope

  • Denial-of-service, spam, social engineering, and physical attacks
  • Third-party systems not operated by Freightbox
  • Automated scanner output without manual validation
  • Low-impact missing headers without a concrete exploit path

How to report

Email security@getfreightbox.com with a clear description, affected asset, reproduction steps, impact, and screenshots or proof of concept where useful.