Security practices

What the production service is built to do

A plain description of the controls in the production design. Written as requirements, not marketing — nothing here is claimed as live until it is.

Prototype. There is no backend yet. These are the controls the backend will be required to implement before any server-side tool is enabled.

Reporting a vulnerability

The production site will publish a /.well-known/security.txt with a contact address and disclosure policy. Until then, please use the contact route on the About page.

Deliberately out of scope

OmniKitly will not include anonymous bulk email sending, address harvesting or scraping utilities. The email category is limited to inspection and validation tools — header analysis, record checks, previews — that help people understand mail they already have.