Security
What we do, and what we do not have.
Koltrix is a young product run by a small team. This page is written so you can tell the difference between what is implemented and what is aspiration.
Implemented today
- Each workspace in its own database schema
- Not a tenant_id column on shared tables — a separate PostgreSQL schema per workspace, provisioned when the workspace is created. A test in our suite fails if a connection is ever handed to one workspace pointed at another's schema.
- Sessions that expire
- Cookie sessions on a 30-day sliding window, HttpOnly and SameSite, with CSRF protection on every cookie-authenticated mutation.
- Scoped API keys
- Each key carries its own permissions, so a key that only sends cannot read mail. Keys are shown once and stored hashed.
- Encryption in transit
- HTTPS everywhere, and opportunistic TLS on SMTP in both directions.
- Outbound mail is signed
- DKIM signing happens on the mail server, so every message leaves signed regardless of which path sent it.
- Rate limits on the paths that matter
- Authentication, search, AI and the image proxy are rate limited per user, with a Retry-After header rather than a silent drop.
- Security headers and a content security policy
- HSTS, nosniff, frame-ancestors, referrer policy and a CSP, with dependency scanning (govulncheck and npm audit) on every build.
- Remote images proxied, trackers stripped
- Images in email are fetched through our proxy so your IP address is not handed to the sender, and known tracking pixels are removed.
- Agents cannot act
- The agent runtime has no tool that can send, forward or delete a message. It is not a setting; the capability does not exist.
Where your email content goes
The honest version, because “we use AI” hides the part that matters.
- Sorting and spam scoring send the headers, the subject and a truncated body to OpenRouter (TypeSafe's Jev model).
- Summaries and drafts send the same to OpenRouter (Google Gemini and DeepSeek models).
- Nothing else is sent. Attachments never leave our servers for an AI provider, and quoted history is stripped before a body is sent.
- Neither provider is permitted to train on your content under our agreements with them.
- You can switch AI off for a whole workspace. Sorting then falls back to our own spam engine and no message content leaves our servers at all.
The full list is on the subprocessors page.
What we do not have
- No SOC 2, ISO 27001 or any other third-party certification. We have not been audited, and we will not imply otherwise.
- No SSO or SAML.
- No two-factor authentication yet. It is a priority, and it is not shipped.
- No dedicated sending IP.
- No published penetration test.
- Off-site backups are being set up; do not treat Koltrix as your only copy of business-critical mail until we say they are running. You can export everything at any time.
Reporting a vulnerability
Email [email protected] with “security” in the subject. We will acknowledge within two business days and tell you what we are doing about it.
- Please do not run automated scans against production, and do not access data that is not yours.
- We do not run a paid bounty programme. We will credit you if you want to be credited.
- Privacy and data-subject requests go to [email protected].
Infrastructure is operated by OVHcloud in Frankfurt, Germany (European Union).