Security at Lew
Lew works with your email and calendar, so security is not a feature we add later. These are the controls in place today.
Your account
- Passwords are hashed with Argon2id, the algorithm recommended by OWASP. We never store or log them in plain text.
- Breached passwords are refused. New passwords are checked against known data breaches using a privacy-preserving lookup: only the first five characters of a one-way hash ever leave our servers.
- Email confirmation is required before an account can be used.
- Password reset links work once, expire after 30 minutes, and signing in again is required on every device after a reset. We email you whenever your password changes.
- Sign-in protection: repeated failed attempts are rate-limited per account and per network, and our responses never reveal whether an email address has an account.
- Sessions use secure, HttpOnly cookies that scripts cannot read, expire after inactivity, and can be reviewed and signed out from Settings.
- Activity log: you can see recent sign-ins and security changes on your account.
Your connected accounts
- You approve every send. Lew can draft emails, but only you can send them.
- Least privilege. We ask Google only for the access Lew needs, and you can revoke it at any time from Lew or from your Google account.
- Tokens encrypted at rest. Google access tokens are encrypted separately from the rest of the database.
- No training on your data. Your email and calendar content is used only to carry out your requests, and never to train AI models.
- Prompt-injection safeguards. Email content is treated as information, never as instructions. A message that asks Lew to forward, pay or share something will not be acted on.
- No human access to your email content, except with your explicit permission for support, when required for security investigations, or when required by law.
Infrastructure
- All traffic uses HTTPS with HSTS. The app and API send strict security headers, including a Content Security Policy.
- Every request that changes data is protected against cross-site request forgery.
- Data is encrypted in transit and at rest, and backed up regularly.
- Production access is limited to the people who need it, with multi-factor authentication.
Reporting a vulnerability
If you believe you have found a security issue, please email security@asklew.com. We will acknowledge your report promptly and keep you updated. Please give us a reasonable time to fix the issue before disclosing it, and do not access other people's data while testing.