SuperMailbox · Updated October 3, 2026

Security at SuperMailbox

How the service is designed to protect mailbox access and the controls available to account owners.

Draft for launch review. These service disclosures still need final company, retention, infrastructure, and contact details before publication.

Security principles

  • Mailbox access is tied to your SuperMailbox account and the AI authorizations you approve.
  • iCloud connections use Apple app-specific passwords. SuperMailbox should never request your primary Apple Account password.
  • Credentials are designed to be encrypted at rest and excluded from logs, analytics, and traces.
  • Email content and attachments are accessed on demand and are not intended to be stored by default.
  • AI permissions can be reviewed and revoked. Mailboxes can be disconnected, and accounts can be deleted from the dashboard.

Current implementation status

This page is a launch draft. The controls above describe the intended service and must be checked against the deployed encryption key management, network configuration, database backups, log redaction, access reviews, and deletion jobs before they are represented as completed controls.

Report a security issue

Please report suspected vulnerabilities or unauthorized access through [security contact to be published before launch]. Include enough detail to reproduce the issue, but do not send mailbox passwords, sign-in links, email contents, or access tokens in a report.

Provider and account safety

Keep your SuperMailbox sign-in email secure. Revoke an AI app you no longer use, disconnect mailboxes you no longer want connected, and replace an app-specific password if you think it has been exposed. Your email provider may show its own app-password and access controls.

Service status

A production security contact, incident communication process, and service status link will be added before general availability.