Skip to content

Security

Report a vulnerability.

Write security@zanonmail.com. There is no bug-bounty programme.

Contact

What to send

Product or infrastructure issues that could put accounts, mail, or billing mappings at risk. Include steps that do not require us to guess, and avoid sending customer mail contents.

What not to do

Do not access other people’s mailboxes. Do not degrade the service. Do not request a bounty. Do not publish an exploit before we have had a chance to look.

Response

We read this inbox. We do not publish a timed SLA for first reply. A security.txt file is at /.well-known/security.txt.

ZanonMail is operated by Zentrix Data, a company licensed in the United Arab Emirates. Last updated 18 August 2026. These pages describe how the product works today. They are not a substitute for counsel and should be reviewed by a lawyer before they are treated as final.