Your mailbox password
You sign in with the address and password of a mailbox you already have. We verify it against your provider's IMAP server, then store it encrypted at rest with AES-256-GCM using a key that lives only on the API server, never in the database.
The password is used solely to connect to your provider. It is never displayed again, never sent to the browser, and deleting the mailbox deletes it.
Reading mail safely
Every message renders inside a sandboxed frame. Scripts, forms and event handlers are stripped. Remote images are held back until you choose to load them, so senders cannot track opens by default.
Inline images and attachments are streamed through the API with short-lived tokens; nothing is hosted publicly.
Sender authentication and phishing checks
For every message we read the SPF, DKIM and DMARC verdicts your receiving server recorded and show them next to the sender: Verified, Unverified or Suspicious.
On top of that, plain-English heuristics flag look-alike domains (including homoglyphs and punycode), Reply-To addresses that differ from the sender, display names that imitate someone you already correspond with, well-known brands sent from free-mail addresses, and wording that asks to change bank details or verify a password. The warning explains exactly why, and Block / Junk are one click away. You can also route high-risk mail automatically with an Automation.
Unsubscribe without exposing yourself
When a sender supports RFC 8058 one-click unsubscribe, the request is sent from Lacspace Mail's servers — your browser never visits the sender. Otherwise we email the list's unsubscribe address from your mailbox, or open the sender's page for you. Muting a sender never contacts them at all.
Automations and webhooks
Automations run on the server when mail arrives. Webhooks you configure receive a JSON POST with the rule and message headers — never the body — signed with your secret (HMAC-SHA256, `t=…,v1=…`) and retried on failure. Destinations on private networks are refused. Auto-reply and forward actions never run retroactively on old mail.
Lumi AI
Lumi only sees the message, draft or attachment you explicitly ask about, at the moment you ask. Nothing is sent to an AI provider in the background, and no mail is used to train models. Summaries, action items and the pre-send review also work with no AI provider at all, using Lacspace's own extractive engine.
Notifications
Web Push uses VAPID keys generated on the server; the push payload contains the sender and subject only and is encrypted end to end to your browser (RFC 8291). Each device can be removed from Preferences.
Accounts, roles and audit
Access is per mailbox: owners, admins and members of a workspace see exactly what they are given. Sign-ins, mailbox changes, sends, unsubscribes and automation runs are logged. Only domains Lacspace has enabled can sign in.
Reporting a problem
Found something? Write to security@lacspace.com. We answer within two working days.