Defense in depth, without theatre.
Asterix combines application controls with a container-isolated data plane. This page describes current design controls without promising that any internet service is risk-free.
Authentication
This private deployment accepts only the linked Google identity for guysleiman@gmail.com. Google sign-in uses authorization code flow, PKCE, state, nonce, strict issuer and audience checks, and verified identity claims. Local password sign-in and the separate authenticator challenge are disabled.
Sessions and request integrity
Sessions are stored server-side in authenticated Redis. Browser cookies are HTTP-only, Secure on HTTPS, and SameSite=Lax. Mutating API requests require a same-origin custom header, and WebSocket upgrades validate both the session and expected origin.
Encryption and isolation
Mailbox passwords, OAuth secrets, and TOTP seeds are encrypted with a deployment key kept outside the database. PostgreSQL and Redis have no public listener and run on an internal container network. Application containers run without root, with read-only filesystems, dropped capabilities, and no-new-privileges.
Mailbox boundaries
Queries scope accounts, messages, folders, contacts, and preferences to the authenticated user. Outbound IMAP, SMTP, OIDC, CardDAV, and AI endpoints are validated to reduce server-side request forgery risk. Email HTML is sanitized and remote images are controlled by user policy.
Responsible disclosure
Do not include mailbox content, passwords, tokens, or personal data in a report. Follow the private reporting instructions in SECURITY.md or contact guy@yourf.com.