Security posture

Small online surface, strict evidence boundaries.

Heavy acquisition and analytical work stays offline. The Worker serves indexed, release-bound projections and private resources only after server-side authorization.

Architecture

Controls in the design

  • Fixed official-source allowlists; no generic arbitrary URL fetch endpoint.
  • Security headers, same-origin checks, bounded request bodies, and route-class rate limiting.
  • Sanitized source narratives and safe official-source link validation.
  • Signature-verified, idempotent payment webhooks and purchase-bound report tokens.
  • Private reports use no-store caching and authorization is enforced server-side.

Pre-production boundary

Reporting and review status

This page is not a security certification, penetration-test result, or production launch claim. No public vulnerability-reporting contact is published until an owner and response process are formally approved.