Security and reporting
ReptiMail security measures and the channel for reporting incidents or abuse.
Connection security
The site must be used over HTTPS. IMAP/SMTP connections use TLS and certificate verification according to configured server settings.
Secret protection
External passwords are not kept in localStorage. The backend encrypts session secrets using libsodium when available or AES-256-GCM via OpenSSL.
Sessions
Web sessions are time-limited. Inactive sessions expire and external accounts must then be reconnected.
Report a vulnerability
To responsibly report a vulnerability, data leak or abuse: contact@reptileblade.tech. Do not publish personal data or secrets in a public report.
Personal data incidents
When a personal data breach creates relevant risk, ReptiMail applies documentation and, where legally required, supervisory authority and data subject notification obligations under the GDPR.
If a translation differs from the French legal documents, the French version is the reference version.
