Extension
- Keys and tokens live in the background worker, never the page.
- The Gmail page can’t change settings or sign in.
- Cloud errors stay errors. No silent fallback.
Cloud
- Sign-in uses OAuth with PKCE.
- Your account comes from a verified token, never the client.
- Row-level security on every table.
- Sensitive data sealed with AES-256-GCM. API tokens hashed.
- Stripe webhooks verified. Outgoing webhooks signed.
Sending
Local can’t send, delete or mark spam without you. Cloud sends only what you approved, checked again before it goes. New rules start in Shadow Mode.
Report an issue
Follow SECURITY.md. Known limits are in the threat model.