Security Center

Learn about our protocols, server deployment, data protection, and platform compliance.

1. Cloudflare Edge Server Infrastructure

InboxRisk is deployed entirely on Cloudflare edge serverless infrastructure. This provides distinct benefits for speed and security:

  • Global Anycast Network: API queries are processed close to the requesting servers, reducing latency and mitigating DDoS attacks at the edge.
  • Serverless Sandboxing: Dynamic check requests execute in isolated V8 Worker isolate environments, eliminating server configuration vulnerabilities.
  • Cloudflare D1 Database: Stored threat intelligence is distributed, encrypted at rest, and replicated.

2. Data Encryption in Transit & at Rest

We protect communications and databases using industry-leading encryption parameters:

  • HTTPS / TLS 1.3: All inbound and outbound traffic to our website and API endpoints is encrypted using TLS 1.3.
  • One-way Cryptographic Hashing: Scam values (emails, phones) submitted to community blocks are converted to SHA-256 hashes using a salt pattern, rendering it impossible to revert to plain-text values if databases are exposed.
  • Encrypted Backups: Database logs, points records, and payment profiles are backed up daily with AES-256 encryption.

3. API Credentials & Authentication Safety

For users subscribing to our developer plans and using endpoints:

  • Secure Key Generation: API credentials are cryptographically random strings generated securely server-side.
  • OAuth Verification: Dashboard login relies on Google OAuth credentials. We do not store or collect passwords on our servers.
  • Strict Rate Limiting: Endpoints are protected by rate limiting filters. Malfunctioning or compromised API keys are suspended automatically if traffic patterns indicate a leak.

4. Responsible Disclosure (Bug Bounty Program)

We value the contributions of security researchers. If you identify a security issue, vulnerability, or leak within our platform, we encourage you to report it immediately.

  • Please submit your findings directly to security@inboxrisk.com with detailed reproduction steps.
  • Allow us reasonable time to investigate and apply updates before public disclosure.
  • We do not pursue legal action against researchers acting in good faith and complying with disclosure guidelines.

Reporting Active Vulnerabilities

Need to send encrypted details? Contact us to request our PGP public keys. Send reports to security@inboxrisk.com.