Security that earns trust
Security statements should be useful and verifiable. This page explains the controls implemented by this public information site and avoids claims about the main application that have not been independently confirmed here.
Public-site protections
The site serves server-rendered content behind restrictive browser security headers. The contact endpoint validates input on the server, bounds the request body, rate-limits submissions, and uses a honeypot and a timing signal.
No secret is included in the client bundle, and no contact message is logged by the application.
- HTTPS required in production
- Content Security Policy
- Clickjacking protection
- Server-side validation
- Dependency review
Responsible disclosure
If you believe you have found a vulnerability, use the contact page and select the security guidance link. Please include clear reproduction steps and avoid accessing data that does not belong to you.
There is currently no public bug-bounty programme or payment promise.
Main application boundary
Authentication, authorisation, encryption, retention and account-deletion controls for the main application require a separate product security review before detailed public claims are added.