Security
The site is built to a conservative security posture: minimal attack surface, no third-party code by default, and a clear channel to report problems.
Headers & policy
The site sets a strict Content-Security-Policy and security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and HSTS). It loads no third-party scripts, fonts or trackers by default.
Forms & uploads
Form input is validated server-side and protected by a honeypot and a per-IP rate limit. File upload is disabled, and no sensitive or research data should be submitted through public forms.
Secrets & accounts
No secrets are exposed in client code — only public configuration reaches the browser — and there are no user accounts in this phase.
Vulnerability disclosure
To report a vulnerability, contact the security address below. Please allow reasonable time for remediation before public disclosure.
Research misuse
We weigh the misuse potential of any release and withhold detail where the risk outweighs the benefit.