Asterix
FeaturesPrivacySecurity
Sign inCreate account
Security

Defense in depth, without theatre.

Asterix combines application controls with a container-isolated data plane. This page describes current design controls without promising that any internet service is risk-free.

Authentication

This private deployment accepts only the linked Google identity for guysleiman@gmail.com. Google sign-in uses authorization code flow, PKCE, state, nonce, strict issuer and audience checks, and verified identity claims. Local password sign-in and the separate authenticator challenge are disabled.

Sessions and request integrity

Sessions are stored server-side in authenticated Redis. Browser cookies are HTTP-only, Secure on HTTPS, and SameSite=Lax. Mutating API requests require a same-origin custom header, and WebSocket upgrades validate both the session and expected origin.

Encryption and isolation

Mailbox passwords, OAuth secrets, and TOTP seeds are encrypted with a deployment key kept outside the database. PostgreSQL and Redis have no public listener and run on an internal container network. Application containers run without root, with read-only filesystems, dropped capabilities, and no-new-privileges.

Mailbox boundaries

Queries scope accounts, messages, folders, contacts, and preferences to the authenticated user. Outbound IMAP, SMTP, OIDC, CardDAV, and AI endpoints are validated to reduce server-side request forgery risk. Email HTML is sanitized and remote images are controlled by user policy.

Responsible disclosure

Do not include mailbox content, passwords, tokens, or personal data in a report. Follow the private reporting instructions in SECURITY.md or contact guy@yourf.com.

Asterix

One secure view for every inbox you manage.

PrivacyTermsSecuritySourceAGPL licenseNoticesDependency licenses
© 2026 YOURF SASU · SIREN 929 129 99731 avenue de la Bourdonnais, 75007 Paris · guy@yourf.com