Security posture
- Transport: TLS 1.2/1.3 only; modern ciphers; HSTS preload.
- Headers: CSP, HSTS, Referrer-Policy, Permissions-Policy, X-Content-Type-Options, X-Frame-Options, X-DNS-Prefetch-Control.
- Hosting: static CDN; immutable assets with cache-busting; origin locked.
- Ops: MFA for admins; key rotation; audit logs; least privilege; dependency pinning; SRI for third-party where unavoidable.
Apps with uploads use signed URLs, AV scanning, and object-level access logs; not this brochure site.