Transport
TLS via Cloudflare, HSTS, HTTPS redirects, modern TLS only.
This site is designed to be boringly secure: HTTPS-only, strict headers, minimal attack surface, and edge delivery.
TLS via Cloudflare, HSTS, HTTPS redirects, modern TLS only.
CSP, frame denial, nosniff, referrer policy, permissions policy, COOP/CORP.
Static assets + thin Worker logic. No database on the public site by default.
Contact endpoint rate limits and method restrictions.
Please report security issues privately via the contact listed in /.well-known/security.txt. Give us reasonable time to remediate before public disclosure.