Skip to content
VelBemaxBack to home
Security

Security & vulnerability disclosure

Security is treated as an engineering responsibility. This page documents the current public disclosure path and the controls implemented in the website.

Report a vulnerability

Security researchers can use the reporting channel listed in security.txt. Please avoid publicly disclosing an unpatched vulnerability before the issue has been reviewed.

Current technical controls

  • HTTPS-only transport with HSTS response headers.
  • Clickjacking protection through frame-ancestors and X-Frame-Options.
  • MIME-sniffing protection through X-Content-Type-Options.
  • Restrictive Referrer and Permissions policies.
  • Content Security Policy restricting scripts, frames, connections, and other resource classes.
  • Dependency and production-build verification in CI.

Scope and limitations

These controls describe the current web application. They are not a claim of SOC 2, ISO 27001, PCI DSS, or other independent certification. No certification, uptime guarantee, registered corporate entity, or security service-level commitment is claimed unless separately published and independently verified.

Security updates

The security page and security.txt file will be updated when the public disclosure process materially changes.