Security
Security & vulnerability disclosure
Security is treated as an engineering responsibility. This page documents the current public disclosure path and the controls implemented in the website.
Report a vulnerability
Security researchers can use the reporting channel listed in security.txt. Please avoid publicly disclosing an unpatched vulnerability before the issue has been reviewed.
Current technical controls
- HTTPS-only transport with HSTS response headers.
- Clickjacking protection through
frame-ancestorsandX-Frame-Options. - MIME-sniffing protection through
X-Content-Type-Options. - Restrictive Referrer and Permissions policies.
- Content Security Policy restricting scripts, frames, connections, and other resource classes.
- Dependency and production-build verification in CI.
Scope and limitations
These controls describe the current web application. They are not a claim of SOC 2, ISO 27001, PCI DSS, or other independent certification. No certification, uptime guarantee, registered corporate entity, or security service-level commitment is claimed unless separately published and independently verified.
Security updates
The security page and security.txt file will be updated when the public disclosure process materially changes.