Small public surface

Security

The production deployment is an allowlisted static build. Source files, tests, dependencies, Git metadata, environment files, and local deployment state are outside the public asset directory.

Browser-only architecture

There is no application server, database, authentication system, file upload, or protected API. Vue renders user labels as text, inputs are length- and range-bounded, and shared state has a strict size and shape limit.

Response protections

Production responses use a Content Security Policy, clickjacking protection, MIME-sniffing protection, a restrictive permissions policy, same-origin resource policy, and a privacy-preserving referrer policy.

Report a vulnerability

A public security-reporting channel is not configured yet. Do not test in a way that degrades availability or accesses data that is not yours. This page will be updated when a dedicated reporting channel is available.

Last reviewed: July 20, 2026. Product functionality and disclosures should be reviewed whenever third-party services or data flows change.