Security & Trust
Security policy

Responsible Disclosure Policy

If you believe you have found a security vulnerability in a Better Email system, write to [email protected]. We acknowledge every report within 2 business days, and we will not pursue legal action against researchers who follow this policy.

Better Email ApS · CVR 42361194 · Last updated September 2026 · Machine-readable version at /.well-known/security.txt

1. Our commitment

Independent security research makes our customers safer. When you report a vulnerability in line with this policy:

  • We acknowledge your report within 2 business days.
  • We give you an initial assessment, including severity and whether the issue is in scope, within 10 business days.
  • We keep you informed of progress while we work on a fix and tell you when it has shipped.
  • We aim to resolve critical issues within 30 days and other confirmed issues within 90 days.
  • We agree a disclosure date with you once a fix is live, and we credit you if you wish.

2. Scope

This policy covers systems that Better Email ApS owns and operates:

  • better.email and www.better.email (this website)
  • app.better.email and api.better.email (the Better Email platform and API)
  • auth-api.better.email (authentication)
  • mcp.better.email (the Better Email MCP server)
  • learn.better.email, assets.better.email, status.better.email
  • The Better Email CLI and any official SDKs or MCP clients published by Better Email

Systems operated by our sub-processors (for example WorkOS, Stripe, Cloudflare or Heroku) and our customers' own environments are outside scope. Please report issues in those systems to the relevant operator. If a third-party issue has a direct impact on Better Email or customer data, tell us as well and we will coordinate with the operator.

3. How to report

Email [email protected] or use the form at the bottom of this page. So that we can reproduce the issue, include:

  • The affected system, URL, endpoint or feature.
  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, a proof of concept, or screenshots. Email these rather than putting them in the form.
  • Your name or handle and how you would like to be credited, if at all.

Please do not include other people's personal data or customer content in a report. If you came across such data while testing, tell us what you saw and delete it.

4. What we ask of you

  • Test only against accounts and data you own, or are expressly authorised to use. Free trial accounts are fine.
  • Stop and report as soon as you can demonstrate the issue. Do not go further than needed to prove it.
  • Do not access, modify, delete or exfiltrate data that is not yours. If you reach such data by accident, stop and tell us.
  • No denial of service, load testing, spam, social engineering, phishing or physical attacks.
  • Do not test our sub-processors or our customers' environments.
  • Give us a reasonable time to fix the issue before disclosing it publicly. We agree the date with you; our default is 90 days after your report.

5. Safe harbour

Better Email will not pursue civil action, or refer to law enforcement, security research that is carried out in good faith and in line with this policy. We consider such research authorised, and we will not claim it breaches our Terms of Service or the anti-circumvention provisions of applicable law. If a third party takes legal action against you for research that complied with this policy, we will make it known that you acted in accordance with it.

This policy does not authorise activity that is illegal under Danish law or the law of your own country. If you are unsure whether something is covered, ask us first.

6. Out of scope

We do not treat the following as vulnerabilities on their own:

  • Findings from automated scanners with no demonstrated impact.
  • Missing security headers or best-practice configuration on pages with no sensitive functionality.
  • Clickjacking on pages with no state-changing actions.
  • Rate limiting, email enumeration or password policy reports without a working attack.
  • Issues in third-party software that we cannot fix ourselves, unless you show impact on our systems.
  • Reports about SPF, DKIM or DMARC on domains that do not send mail.

7. Credit and rewards

We do not run a paid bug bounty programme. We do credit researchers who report valid issues on this page, with their permission, once the fix is live. For high-impact findings we may offer a discretionary thank-you.

Submit a report

Prefer email? Write to [email protected]. This form takes a short summary so we can open a case and reply from a monitored mailbox. Send reproduction steps, proof of concept and screenshots by email rather than through the form. Do not include credentials, personal data or customer content.