Security

Report privately.
Include no real mail.

PhishCues welcomes responsible vulnerability reports for the current public beta.

01 / Reporting

Use one monitored private contact.

Contact

Email admin@phishcues.com with the subject Private PhishCues security report. Include the affected version, synthetic reproduction steps, expected impact, and whether the wrong message, account, identity, or private data may be involved.

Never send

Do not include passwords, passkeys, tokens, private keys, full emails, raw headers, attachments, private report capabilities, unredacted personal data, or an exploit that causes unnecessary harm.

Highest priority

Wrong-message or wrong-account binding, unauthorized identity claims, exposed private evidence, bypassed owner access, secret compromise, reporting without consent, and failure to honor deletion or emergency disable are handled as critical.

Good-faith boundary

Use synthetic accounts and the minimum testing necessary. Do not access another person's data, disrupt service, persist access, demand payment, or publicly disclose a live issue before a reasonable remediation window is agreed.

02 / Current status

Internally reviewed. Not independently certified.

The beta has automated, adversarial, privacy-boundary, and release checks. Those checks do not constitute an independent penetration test, legal approval, certification, or guarantee.