Hardening

Security posture

This site is designed to be boringly secure: HTTPS-only, strict headers, minimal attack surface, and edge delivery.

Transport

TLS via Cloudflare, HSTS, HTTPS redirects, modern TLS only.

Headers

CSP, frame denial, nosniff, referrer policy, permissions policy, COOP/CORP.

Surface

Static assets + thin Worker logic. No database on the public site by default.

Abuse controls

Contact endpoint rate limits and method restrictions.

Report a vulnerability

Please report security issues privately via the contact listed in /.well-known/security.txt. Give us reasonable time to remediate before public disclosure.