Trust
Security and protection
This site is built to replace a website builder with a locked-down Next.js app. The protections below are on by default.
Transport and headers
- HTTPS only in production, with HSTS.
- Content-Security-Policy, frame denial, nosniff, referrer trimming, and a tight permissions policy.
- The Next.js version header is turned off.
Intake form
- Server-side validation with a schema. Client checks are not trusted alone.
- Honeypot field and a minimum-time check against dump bots.
- Per-IP rate limiting on the audit endpoint.
- Output is escaped before any HTML email is sent.
- No secrets are shipped to the browser. API keys live in environment variables.
Client systems
Production automations for a client stay in that client's workspace. We do not mix guest or patient data across companies. If your industry has extra rules, we treat that as a design constraint, not a footnote.
Report a problem
Email tyre@alohaislandintel.com with the subject “Security”. Please do not publicly post exploit details. We also publish /.well-known/security.txt.
