Skip to content
FAURITOR

Security

Security is part of the system, not a badge

This page describes the controls implemented in the current repository and the limits of what can be verified before deployment. It is not a certification or security guarantee.

Implementation baseline · review required before publication

Current controls in the repository

  • The contact endpoint uses server-side schema validation, a honeypot, a timestamp trap, origin allowlisting and a Firestore transaction-based rate limit.
  • The browser is not granted direct Firestore access; checked-in Firestore rules deny all direct client reads and writes.
  • Secrets are intended to stay in deployment configuration/Cloud Secret Manager and are not sent to the browser.
  • The hosting configuration includes content-type, frame, referrer, permissions and content-security policy headers, with HTTPS/HSTS requiring deployment verification.
  • Application logs are designed to record event names and identifiers rather than submitted free text or email addresses.

Limits and operational responsibilities

Production security depends on Firebase project permissions, deployment configuration, mail/DNS setup, provider contracts, log access, dependency updates, backups and deletion procedures. None of those external settings is treated as verified merely because a configuration file exists in this repository.

No SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR or WCAG certification claim is made by this site.

Responsible disclosure

To report a suspected vulnerability, email contact@fauritor.com with “Security report” in the subject. Share only the minimum reproducible detail; do not include customer data, credentials, secrets or exploit payloads that could affect other people. We do not promise a reward, response time or acceptance of every report.

Review status

This page is an implementation baseline. The owner and a technical security reviewer must verify the deployed headers, IAM, logs, backups, provider settings, vulnerability status and incident procedure before final publication.