A deliberately small public surface.
The website has no authentication, server-side writes or user data. Vulnerability reports use a private GitHub channel.
Report an issueWebsite architecture
Astro generates static files served by Cloudflare Pages.
- No SSR or application endpoint
- No form or user storage
- Restrictive security headers
StaticOps application
The application API only listens on loopback and local secrets are protected by Windows DPAPI. Never attach a database, ACT log, webhook or FF Logs credentials to a public report.
Report a vulnerability
Use the private Security Advisory form exclusively. Include the version, impact and a minimal sanitized reproduction.
Acknowledgement targetWithin 72 hours