Security
Foyerbox handles the most sensitive thing most people own: their inbox. This is how it is built to protect it.
Encrypted on the way
- Your browser talks to Foyerbox over HTTPS only, with HSTS so it never falls back to plain HTTP.
- Foyerbox talks to your mail providers over TLS: IMAP on port 993, and SMTP with SSL or STARTTLS.
Passwords and tokens are encrypted
- App passwords, sign-in tokens, API keys and integration secrets are sealed with XChaCha20-Poly1305 before they're stored.
- The encryption key is given to the server separately and is never stored in the database or its backups, so a copy of the database alone can't unlock them.
- Your Foyerbox password is stored only as an Argon2 hash.
- Exports never include passwords or tokens.
Where your mail lives
- The copy of your mail Foyerbox keeps is used only to show, sort and summarize it for you.
- The server accepts no connections from the internet. Visits reach it only through an encrypted Cloudflare Tunnel, which also absorbs attacks before they get there.
- Backups are made every day, encrypted before they leave the server, and kept for 7 days.
- Nobody at Foyerbox reads your mail. Access to the servers is limited to the people who run them, with key-based sign-in only.
Your account is protected
- New accounts confirm their email before they can connect any mail.
- Sign-in uses an HttpOnly, Secure, SameSite session cookie. Every change needs a custom header that another website can't send, and the app has a strict Content Security Policy.
- Ten wrong passwords lock an account for 15 minutes, and sign-ups, sign-ins and password resets are rate-limited per network.
- Resetting your password signs out every other session.
- Each account sees only its own mail; every request is checked against the signed-in account.
No reaching into private networks
Foyerbox connects only to mail servers, relays, webhooks and unsubscribe links on the public internet. Addresses on private or internal networks are refused, so nobody can use Foyerbox to reach systems they shouldn't.
Reading mail safely
- Message HTML is shown in a sandboxed frame with scripts disabled.
- Remote images are blocked until you choose to load them, so tracking pixels can't report when you open a message.
- Tags that could load or navigate on their own (redirects, prefetching, frames, forms) are removed, and links open in a new tab that can't reach back into Foyerbox.
- Attachments are always downloaded, never opened as pages inside Foyerbox.
- Fetching mail never marks it read at your provider; only opening it in Foyerbox does.
AI without surprises
- AI is optional and off until you turn it on. Foyerbox's built-in sorting works without it.
- Only the messages a request needs are sent, to Foyerbox AI (Anthropic), which doesn't train on them.
- Mail text is passed as data with an instruction to ignore instructions inside it, which defends against prompt injection in incoming mail.
- AI never sends, deletes or archives anything by itself. You take every action.
Reviews
Each release runs automated attack tests and a check of every dependency against the RustSec advisory database. An internal security review was completed on October 11, 2026 and its findings fixed. An independent penetration test is planned, and its summary will be published here.
Reporting a problem
If you find a security issue, please report it privately rather than in public. Email kevin@exovie.app with the details and how to reproduce it. Reports are acknowledged within three working days, and we'll tell you when it's fixed.