Skip to content

Security

What actually protects this site, the apps and your data — no badges, just the controls in place.

  • Static site on Cloudflare's edge

    This website is pre-built static files served by Cloudflare Pages over HTTPS only. No server-side code or database sits behind the public pages.

  • No exposed backend ports

    Backends are reached only through an outbound Cloudflare Tunnel. Services listen on localhost and are not published directly to the internet.

  • Two locks on the admin

    The control center sits behind Cloudflare Access (email one-time code, allow-list) and then requires its own sign-in with an authenticator-app code (TOTP).

  • Least-privilege data access

    Data lives in PostgreSQL with row-level security on every table. Public clients can only call narrow read functions; admin changes are recorded in an append-only audit log.

  • Protected contact form

    The project form uses Cloudflare Turnstile, a hidden honeypot field, server-side validation and per-IP rate limits.

  • Strict security headers

    Content-Security-Policy, HSTS, no framing, no MIME sniffing and a restrictive Permissions-Policy on every page.

  • Encrypted nightly backups

    Databases are backed up automatically every night and the backup files are encrypted.

  • No ad trackers

    Only cookieless Cloudflare Web Analytics — no advertising trackers, so no cookie banner is needed.

Report a vulnerability

Found a security issue? Email the address below with steps to reproduce. Please allow reasonable time for a fix before public disclosure. There is no paid bug bounty.

Nothing on this page is a certification. Each control is re-checked before every major release.