security

Security

How isBusinessEmail protects API keys, the addresses you check and your account, and how to report a vulnerability to security@isbusinessemail.com.

Report a vulnerability

Email security@isbusinessemail.com. Our contact details are also in /.well-known/security.txt.

Please include:

  • what you found and where (URL, endpoint, parameter)
  • steps to reproduce, or a proof of concept
  • the impact as you understand it
  • how to reach you, and how you’d like to be credited

We’ll acknowledge your report within 3 business days, keep you updated, and tell you when it’s fixed. We don’t run a paid bug bounty, but we’re glad to credit reporters (with permission) once a fix ships.

Safe harbor

If you act in good faith, follow this policy and give us reasonable time to fix an issue before disclosing it, we won’t pursue legal action against you. Good faith means:

  • Test only against your own account and your own API keys.
  • Don’t access, change or delete other people’s data. If you hit someone else’s data by accident, stop, and tell us.
  • Don’t degrade the service: no denial-of-service, load testing, or automated scanning that generates significant traffic.
  • Don’t use social engineering, phishing, or physical attacks against our team or providers.
  • Don’t test our providers’ infrastructure (Cloudflare, Hetzner, Google, Microsoft, Brevo); report issues in their systems to them.

Out of scope

  • Reports from automated scanners without a demonstrated impact
  • Missing security headers on pages with no sensitive actions, unless you show an exploit
  • Rate limiting on the public checker (it’s deliberately limited and monitored)
  • Self-XSS, clickjacking on pages without sensitive actions, logout CSRF
  • Our verdicts being wrong; that’s feedback, not a vulnerability

What we protect, and how

The addresses you check

  • Never stored in clear text. We keep the domain and an HMAC of the local part with a secret pepper.
  • Redacted from logs. Request logs strip email, Authorization, X-API-Key and cookies.
  • No mailbox probing. We never contact your users’ mail servers or ask providers about them.
  • The blocklist can’t be harvested. Exact-address blocklist results go to secret-key holders only, sweeps are flagged, and hashes are never exported.

API keys

  • Shown once; only a SHA-256 hash is stored.
  • A built-in checksum rejects malformed keys before any lookup.
  • Revocation takes effect everywhere within 60 seconds.
  • Leaked secret keys found by GitHub secret scanning are revoked automatically and you’re notified.
  • Publishable keys work only from the origins you allow, with a reduced response and low limits.

Your account

  • No passwords to steal: sign-in with Google, Microsoft or a one-time email link.
  • Sessions are hashed server-side, in __Host- cookies that are HttpOnly and Secure; state-changing requests require a matching Origin.
  • Microsoft sign-in is protected against email-claim spoofing (accounts are keyed on tenant and object IDs unless the email is verified).
  • You get an email on new sign-ins, and you can revoke sessions.
  • Self-service data export and account deletion.

Infrastructure

  • The website and API run on Cloudflare Workers, behind Cloudflare’s DDoS protection, WAF and rate limits.
  • The database runs on Hetzner in the EU, with no public ports: it’s reachable only through an outbound Cloudflare Tunnel protected by an access token.
  • Least-privilege database credentials; secrets live in the platform’s secret store, never in git.
  • Nightly encrypted backups, with restores tested regularly.
  • A strict Content Security Policy, HSTS, frame-ancestors 'none' and a strict Referrer-Policy on the website.
  • Dependencies are kept minimal and monitored for known vulnerabilities.

Abuse resistance

  • The public checker requires a human check (Turnstile), uses signed short-lived passes, and escalates from slowdowns to bans for automated use.
  • Lookups only ever target a domain’s registrable domain, with per-domain caps, so our service can’t be used to flood someone’s DNS.
  • Admin actions are audited.

Incidents

If an incident affects your data, we’ll notify affected customers without undue delay and, where required, the supervisory authority within 72 hours. Service status: status.isbusinessemail.com.

Related: Privacy Policy · Subprocessors · Privacy and data