Problem
Someone who wants to work with InOrbit has one way in: an e-mail address on the contact page. That works for a person who already knows what to write. It does not tell a visitor what we take on, it asks them to switch to their mail client, and it gives us no structure (what it is about, which company) when the message arrives.
The owner asked for a page where anyone can write about working together, delivered to the founder's inbox.
Proposal
The page
A public page, Working together, linked from the contact page and the footer. It names what people write about: a pilot on their system, a partnership, a contract, a role, or something else. Then one form: the topic, their name, their company (optional), their e-mail and the message (10 to 2000 characters). A line under the form says what happens to the message, and the plain e-mail address stays beside the button for anyone who prefers it.
Delivery, and nothing kept
The form posts to the accounts service, which needs no sign-in for this one call. It checks every field (lengths, one line for names, a real address, a known topic) and mails the message to the company's configured address through the same relay as the sign-in mail. The visitor's address is at the top of the mail, so the founder answers them directly.
Nothing is stored: no table holds these messages, and the mail is the only copy. The relay's own log keeps that a mail went out to the company, as for every mail it sends.
A diagram is drawn here in the RFCs product; this page does not show diagrams yet.
Abuse
- The edge limits how often one address may send, and the call accepts POST only.
- A field people never see (it is hidden from screen readers too) is filled only by form fillers. Such a message gets the same answer as any other and is mailed nowhere, so a bot learns nothing from the reply.
- The relay's caps on one recipient bound how many mails reach the inbox in an hour and a day, whatever the edge lets through.
- The request carries no cookie and no sign-in.
Data and audit
The name, company, address and message are personal data. They travel in the request and the mail only. Audit lines carry a short hash of the client address, the topic and the outcome (sent, held by the relay's caps, or dropped by the hidden field); never the message, the name, the company or the address. The page's privacy line says this.
Alternatives considered
- A mail link only. What exists today. No structure and no topic, and the visitor leaves the page for their mail client.
- A form behind sign-in. No anonymous endpoint to abuse, but it asks a stranger to make an account before saying hello.
- A third-party form service. Another vendor holding the visitor's message and address, for a form our own relay can deliver.
Decision
Decided 2026-10-07. Built on 2026-10-06 and live.
Status log
- 2026-10-06: opened and built at the owner's request: the page, the call on the accounts service, the edge's limit and the guard test that pins it.
- 2026-10-07: Decided: built and live (#414 in accounts, the edge and www).