Security posture
Small online surface, strict evidence boundaries.
Heavy acquisition and analytical work stays offline. The Worker serves indexed, release-bound projections and private resources only after server-side authorization.
Architecture
Controls in the design
- Fixed official-source allowlists; no generic arbitrary URL fetch endpoint.
- Security headers, same-origin checks, bounded request bodies, and route-class rate limiting.
- Sanitized source narratives and safe official-source link validation.
- Signature-verified, idempotent payment webhooks and purchase-bound report tokens.
- Private reports use no-store caching and authorization is enforced server-side.
Pre-production boundary
Reporting and review status
This page is not a security certification, penetration-test result, or production launch claim. No public vulnerability-reporting contact is published until an owner and response process are formally approved.