Vulnerability Disclosure

Effective August 15, 2026 · Last updated August 15, 2026

Aero holds a live connection to a mailbox somebody depends on. If you find a way to break that, we want to hear about it before anyone else does. This page says how to tell us, what we will do about it, and what we promise not to do to you.

How to report

Email security@aeromail.ai. There is no form and no bug bounty platform in between — the address reaches the person who can fix the problem.

Please include:

  • The affected URL, endpoint, or account state.

  • Steps to reproduce, in the order you performed them.

  • What an attacker gains, and roughly how hard it would be to get there.

  • Any proof-of-concept code, screenshots, or request captures you already have.

If the report itself contains sensitive material, say so in the first message and we will send you a way to share it encrypted.

What we will do

  • Acknowledge your report within two business days.

  • Tell you within ten business days whether we consider it a vulnerability, and the fix window we are working to.

  • Keep you updated through resolution, and tell you when the fix ships.

  • Credit you by name in the release note if you would like that, or keep you anonymous if you would rather.

Scope

In scope: app.aeromail.ai, aeromail.ai, our public API, and the Aero desktop and mobile clients.

Out of scope: anything that only affects Google, Microsoft, or another provider’s own systems — report those to the provider directly. Also out of scope are scanner output with no demonstrated impact, missing security headers with no exploit path, rate limiting on unauthenticated endpoints, social engineering of our staff or our users, and physical attacks.

Safe harbor

If you follow this policy in good faith, we will not pursue legal action against you, support anyone else who does, or contact your employer or hosting provider about it. We consider testing done under this policy authorized under applicable computer-misuse law, and we will say so in writing if you need us to.

Good faith means you test only against accounts you own or have permission to use, you stop as soon as you have proof, you do not access, modify, or retain anyone else’s mail, and you give us a reasonable chance to fix the issue before you publish.

Publishing

Write about it whenever you like once the fix has shipped, or ninety days after your report if we have not shipped one. We would rather you told people about a real problem than sat on it indefinitely because we were slow.

Related

How Aero is built to resist these problems in the first place is described on the security page. What we collect and hold is in the privacy policy.