Security model
Controls you can explain
to legal + IT.
Integrity, throttling, and data minimization — focused on what matters for public inboxes.
| Area | Mechanism | Notes |
|---|---|---|
| Verification | HMAC token + TTL | One-time verification link |
| Abuse | Rate limiting | Per sender / route / tenant |
| Privacy | Expiry | Pending mail auto-expires |
| Operations | Route disable | Stops forwarding immediately |