Security posture

Controls described at the stage they actually exist.

This source package makes no certification, audit, uptime, penetration-test, encryption, or production-readiness claim.

Static deployment baseline

  • Static-first Astro output with minimal client JavaScript.
  • The packaged header file specifies content-security, referrer, permissions, content-type, framing, and cross-origin policies.
  • No API handler, delivery provider, Turnstile secret, rate-limit storage, runtime binding, or secret is included in this static deployment. The /api/pilot form destination remains inactive.
  • Cookie-free analytics is disabled until it is configured, reviewed, and disclosed.

Activation gates

Before accepting pilot requests, a separate runtime must be deployed and verified for server-side validation, origin restrictions, request-size limits, honeypot handling, Turnstile, throttling, delivery, logging, and abuse response. This page must then be updated from observed production controls, including HSTS only if it is actually enabled for the custom hostname.

Before real customer data

Real source or document ingestion remains blocked until tenant isolation, access control, upload quarantine, malware scanning, encryption, retention, export, deletion, audit, provider, incident, backup, and recovery controls pass their tests.

Reporting

No security reporting address is represented as active on this static site. A security@ address should be published only after a maintained intake, acknowledgment, escalation, and disclosure process exists.

Customer responsibility

If a pilot form is activated, customers must not place passwords, API keys, payment details, sensitive personal information, confidential records, or production documents in it.