Report security vulnerabilities privately via GitHub Security Advisories on the repository the issue affects:
- naust-mail/naust - the mail server, setup scripts, control-plane daemon, admin UI
- naust-mail/rav - the webmail client
- naust-mail/naust-docs - naust.email (docs site, low severity by nature - no user data flows through it)
If you are unsure which repo an issue belongs to, report it against
naust-mail/naust and it will be redirected.
Do not open a public issue for a security vulnerability.
naust-mail/naust has a full security guide
covering the threat model, TLS configuration, brute-force protection, DNSSEC/DANE,
and spam filtering for a running instance. This org-level policy only covers
how to report an issue - see that document for what a configured box actually protects against.