Browser-only architecture
There is no application server, database, authentication system, file upload, or protected API. Vue renders user labels as text, inputs are length- and range-bounded, and shared state has a strict size and shape limit.
Response protections
Production responses use a Content Security Policy, clickjacking protection, MIME-sniffing protection, a restrictive permissions policy, same-origin resource policy, and a privacy-preserving referrer policy.
Report a vulnerability
A public security-reporting channel is not configured yet. Do not test in a way that degrades availability or accesses data that is not yours. This page will be updated when a dedicated reporting channel is available.