Trust & Policy
Security
A simple site should have a simple attack surface.
Current safeguards
- Static-site architecture with no public user accounts or database in this build.
- HTTPS expected through the hosting provider.
- Restrictive browser security headers prepared for the static hosting layer.
- No third-party analytics or advertising scripts enabled by default.
Report a vulnerability
Please do not exploit, retain or disclose personal data while testing. A monitored security contact must be configured before public launch; use the Contact page once that address is added.