Security
What we actually run today — not a promise of a future control.
- TLS 1.3 on public HTTPS. HSTS preload is off until every host is clean.
- CAA includes Let’s Encrypt. Staff two-factor is available and will be required for admin.
- Stripe webhook signatures; prices are set on the server.
- Mail: SPF, DKIM, DMARC, MTA-STS. Independent support and admin mailboxes.
- Report a vulnerability to [email protected] or see /.well-known/security.txt.