Do not open a public issue for a suspected vulnerability, leaked credential, cross-tenant access, or abuse path.
Email security@agentmailer.ai with “Security” in the subject. Include the affected surface, reproduction steps, impact, and any non-sensitive logs. Remove OAuth tokens, cookies, authorization headers, customer email, and personal data before sending.
We will acknowledge the report, investigate it, and coordinate remediation and disclosure when appropriate. This repository contains packaging and workflow instructions; AgentMailer's hosted service and security controls are maintained separately.