Security notice
Last updated: October 4, 2026.
Kaytos, LLC operates newtab.email. This development build has not completed Google OAuth verification or Chrome Web Store review. Public security information is available at qorsoftware.com/newtab/security/.
Boundaries
- OAuth tokens are managed by Chrome identity and attached only to approved Gmail, People and Calendar HTTPS endpoints. Redirects are rejected; requests have deadlines. Foreground, popup, and background token requests require recorded in-app consent.
- Storage is restricted to trusted extension contexts. Preferences stay local. No content script, arbitrary-site host permission, remote executable code, cloud classifier, or telemetry is included.
- Email HTML is untrusted. DOMPurify sanitizes it before and after formatting; an opaque sandbox with a restrictive CSP renders it. Scripts, forms, embedded frames, and network APIs are unavailable there. Remote images require an explicit allowance.
- Account checks, durable send-attempt records, and database transactions protect against cross-account actions and uncertain retries. The UI must not call an uncertain send successful.
- Calendar caches are bound to the verified token account and hidden when the saved mail profile changes. Browser locks and state revisions prevent pending refreshes from undoing a disconnect or publishing events under a replacement account.
- Local search, heuristics, and optional on-device AI are advisory. A sender's name, a model answer, and public-display masking are not security decisions.
Known release blocker
Local mail, indexes, drafts, preferences, and backups are not encrypted by this application. OS disk protection is outside its control. A secure migration, recovery behavior, multi-tab/background coordination, and protection of sensitive index fields must be designed and verified before claiming encrypted storage. Storing an encryption key beside encrypted values does not protect against full-profile compromise.
Reporting
Report security concerns privately to hello@qorsoftware.com, with the subject Newtab security report. Start with a description, the extension and Chrome versions, and synthetic reproduction steps. Do not send real email, tokens, passwords, private account identifiers, or unsent drafts, and do not post those details in public issues. If additional sensitive evidence is necessary, contact Kaytos first to arrange an appropriate private channel.