Authenticated ownership checks
Protected server functions require a signed-in workspace and verify ownership before domain, mailbox, template or campaign mutation.
This page documents controls represented in the application. It does not claim certifications, encryption modes, authentication factors or bounty payments that have not been independently established.
Protected server functions require a signed-in workspace and verify ownership before domain, mailbox, template or campaign mutation.
Keys are generated with an hm_ prefix, validated by SHA-256 hash, may have an encrypted reveal copy, and can be revoked independently.
Workspace sessions administer the product; mailbox credentials access one mailbox; API keys authorize developer endpoints.
Appwrite service credentials, Paystack secrets and mail-server credentials remain in the server environment rather than public client configuration.
Queries scope operational records to the authenticated user or selected mailbox, with additional ownership checks before changes.
Campaigns validate template ownership and state, audience, duplicate addresses and available credits before final confirmation.
Send a concise report to security@hihemax.com with the affected surface, reproduction steps, impact and safe evidence. Do not access other users’ data, degrade service or publish details before the issue can be investigated.
security@hihemax.comSecurity documentation should evolve with implemented controls and verified external assessments. If a certification or security feature is not listed here, do not assume it is available.
Read operational security guidance