Security
What actually protects this site, the apps and your data — no badges, just the controls in place.
Static site on Cloudflare's edge
This website is pre-built static files served by Cloudflare Pages over HTTPS only. No server-side code or database sits behind the public pages.
No exposed backend ports
Backends are reached only through an outbound Cloudflare Tunnel. Services listen on localhost and are not published directly to the internet.
Two locks on the admin
The control center sits behind Cloudflare Access (email one-time code, allow-list) and then requires its own sign-in with an authenticator-app code (TOTP).
Least-privilege data access
Data lives in PostgreSQL with row-level security on every table. Public clients can only call narrow read functions; admin changes are recorded in an append-only audit log.
Protected contact form
The project form uses Cloudflare Turnstile, a hidden honeypot field, server-side validation and per-IP rate limits.
Strict security headers
Content-Security-Policy, HSTS, no framing, no MIME sniffing and a restrictive Permissions-Policy on every page.
Encrypted nightly backups
Databases are backed up automatically every night and the backup files are encrypted.
No ad trackers
Only cookieless Cloudflare Web Analytics — no advertising trackers, so no cookie banner is needed.
Report a vulnerability
Found a security issue? Email the address below with steps to reproduce. Please allow reasonable time for a fix before public disclosure. There is no paid bug bounty.
Nothing on this page is a certification. Each control is re-checked before every major release.