Security
Security Practices
Version 0.3, effective 30 June 2026.
Website
- HTTPS should be enabled on the production domain.
- Directory listing is disabled by `.htaccess` where supported.
- Security headers are configured for common browser protections.
- The contact form uses reCAPTCHA and server-side validation.
Secrets
SMTP credentials, reCAPTCHA secrets, and API keys must stay in server-side configuration such as `config.local.php`; they must not be placed in public HTML or JavaScript.
Client Work
For enterprise projects, access control, logging, backup, recovery, audit, and operational support are agreed in the project architecture, DPA, and SLA.
Reporting
If you suspect a security issue or impersonation attempt, use the contact form and include only non-sensitive details.
