Security
The posture, documented honestly — what is deployed, what is in scope, and what is not yet done.
Security headers
Verified against the live site. These are applied at the Cloudflare edge.
Forces HTTPS for a year, including subdomains, with preload intent.
The full deployed CSP. Blocks framing (frame-ancestors 'none') and restricts scripts/styles/fonts/images/connections to known origins. 'unsafe-inline' in script-src is a known trade-off for Astro's inline hydration scripts — a nonce pipeline is a P2 improvement.
Disables camera, microphone, and geolocation at the document level.
Sends only the origin, never the full URL, cross-site.
Prevents MIME-sniffing.
Rejects all framing.
Vulnerability disclosure
Report a security issue to trimtab.signal@proton.me or willyj1587@gmail.com. We aim to acknowledge responsible reports promptly. See .well-known/security.txt for the machine-readable disclosure — which carries the plain addresses and is not obfuscated. For how the audit chain maps to audit-logging requirements, see Compliance.
There is no bounty program at this time. We do not pursue legal action for good-faith security research.
Data handling
- No server-side identity store — the did:key is generated and stored on the device.
- The audit chain records that an action happened and by whom, not content — in D1, backed up to R2.
- No analytics, no tracking. The zero-telemetry posture is a documented build gate.
Sub-processors
The honest scope
P31 has not obtained SOC 2 or ISO 27001 certification. This page documents the controls that are in place. Known trade-offs are stated rather than hidden: the CSP uses 'unsafe-inline' for Astro's inline hydration scripts (a nonce pipeline is a P2 improvement), and the passkey worker returns Access-Control-Allow-Origin: * by design — WebAuthn trusts the rpId, not CORS.
Machine-readable disclosure: .well-known/security.txt.