Batmail

Legal

Security and Vulnerability Disclosure

Last updated: August 26, 2026

Batmail holds access to people’s email, so we take reports of security problems seriously. This page tells security researchers what they may test, how to report what they find, and what we will do about it. If you have found something, email support@batmail.ai.

Scope

This policy covers:

  • https://www.batmail.ai and https://batmail.ai, including the marketing site and the signed-in application.
  • The Batmail API endpoints under /api/.
  • The Batmail Google OAuth integration, as it affects Batmail accounts.

Out of scope:

  • Third-party services Batmail depends on. Vercel, Neon, Google, Anthropic, Resend, Crisp, Slack, Stripe and Sentry. Report those to the vendor directly under their own disclosure policy.
  • Other domains and products operated by the same team.
  • Findings that require a compromised device, a malicious browser extension, or physical access to a user’s machine.
  • Reports produced only by an automated scanner, with no demonstrated impact.
  • Missing best-practice headers, cookie flags, or TLS configuration with no demonstrated exploit path.
  • Social engineering of Batmail staff, users, or vendors.

If you are not sure whether something is in scope, email us and ask before you test.

Rules of engagement

We ask that you:

  • Report a real or suspected issue as soon as you find it.
  • Give us reasonable time to fix it before disclosing publicly. Our targets are below.
  • Avoid privacy violations, degradation of service, and destruction or modification of data.
  • Test only against accounts you own or have explicit permission to use. Do not access, modify, or retain another user’s email, tokens, or account data.
  • Use an exploit only as far as needed to prove the vulnerability exists. Do not pivot, do not establish persistence, do not exfiltrate data.
  • Stop immediately if you encounter someone else’s personal data or any credential, tell us, and do not keep a copy.
  • Do not submit high volumes of low-quality or scanner-generated reports.

Prohibited testing

The following are never authorized:

  • Denial of service or distributed denial of service testing, and any test that degrades availability for real users.
  • Physical testing of offices or people.
  • Phishing, vishing, smishing, or any other social engineering.
  • Spam, or bulk automated account creation.
  • Brute forcing credentials of accounts you do not own.

Safe harbour

If you conduct security research in good faith and in accordance with this policy, we consider that authorized. We will not pursue or support legal action against you for it, and we will say so clearly if a third party raises the issue. This authorization does not extend to activity that breaks the rules above.

Reporting a vulnerability

Send reports to support@batmail.ai. Reports may be anonymous. English is preferred. Please include:

  • A description of the vulnerability and why it matters.
  • Where you found it: URL, endpoint, parameter.
  • The potential impact.
  • Clear steps to reproduce, with a proof of concept, screenshots or a short script.
  • Any account identifiers you used, so we can trace your activity in our logs.

What we commit to

Provided you give us a way to reach you:

  • 3 business days to acknowledge your report.
  • 10 business days to triage it and tell you the severity we assessed.
  • 30 days to fix a critical or high severity issue.
  • 90 days to fix a medium or low severity issue, or an explanation of why it will take longer.
  • Confirmation once the fix is live, and credit for you if you want it.

Rewards

Batmail does not currently run a paid bug bounty. We will credit researchers who want it, and we will say thank you properly.