Website Security
Kixavoq is designed as a small static website with a limited attack surface. This page describes the intended production configuration.
Current security design
- No public file uploads, user accounts, database or payment processing.
- No third-party JavaScript libraries loaded from remote domains.
- No affiliate redirect scripts, click trackers or device-specific destinations.
- Security headers supplied through Cloudflare Pages using the
_headersfile. - A SHA-256 integrity manifest included with the deployment package.
- A public security.txt contact file.
Report a security issue
Email [email protected] with the subject “Kixavoq security report”. Include the affected URL, steps to reproduce and potential impact. Do not access, modify or retain data that does not belong to you.
No vulnerability bounty promise
Submitting a report does not create a contract or guarantee payment. We nevertheless welcome good-faith reports that help protect visitors.