Skip to content
Security practices for the website and delivered systems

Security

Security is handled as an engineering requirement across architecture, code, data, integrations and operations.

Website protections

  • Strict transport security in production
  • Content-type and frame protections
  • Controlled permissions policy
  • Same-origin form validation
  • Request size and rate limits
  • Dependency and build verification

Product security

  • Threat modelling
  • Least-privilege access
  • Tenant isolation where applicable
  • Secret management
  • Audit logging
  • Backup and recovery procedures

Responsible disclosure

Security findings related to this website can be reported through the address published in /.well-known/security.txt. Please avoid accessing or changing data that does not belong to you.

No false guarantees

No system can be described as absolutely secure. The goal is to reduce risk, detect failures quickly and maintain a clear response path.