Security

The posture, documented honestly — what is deployed, what is in scope, and what is not yet done.

Security headers

Verified against the live site. These are applied at the Cloudflare edge.

Strict-Transport-Security
max-age=31536000; includeSubDomains; preload

Forces HTTPS for a year, including subdomains, with preload intent.

Content-Security-Policy
default-src 'self'; script-src 'self' 'unsafe-inline' blob: https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: blob: https:; connect-src 'self' https: wss: blob: data:; worker-src 'self' blob:; frame-ancestors 'none';

The full deployed CSP. Blocks framing (frame-ancestors 'none') and restricts scripts/styles/fonts/images/connections to known origins. 'unsafe-inline' in script-src is a known trade-off for Astro's inline hydration scripts — a nonce pipeline is a P2 improvement.

Permissions-Policy
camera=(), microphone=(), geolocation=()

Disables camera, microphone, and geolocation at the document level.

Referrer-Policy
strict-origin

Sends only the origin, never the full URL, cross-site.

X-Content-Type-Options
nosniff

Prevents MIME-sniffing.

X-Frame-Options
DENY

Rejects all framing.

Vulnerability disclosure

Report a security issue to [email protected] or [email protected]. We aim to acknowledge responsible reports promptly. See .well-known/security.txt for the machine-readable disclosure — which carries the plain addresses and is not obfuscated. For how the audit chain maps to audit-logging requirements, see Compliance.

There is no bounty program at this time. We do not pursue legal action for good-faith security research.

Data handling

  • No server-side identity store — the did:key is generated and stored on the device.
  • The audit chain records that an action happened and by whom, not content — in D1, backed up to R2.
  • No analytics, no tracking. The zero-telemetry posture is a documented build gate.

Sub-processors

Cloudflare
Edge network — Pages, Workers, D1, TLS, DDoS mitigation
GitHub
Open-source source hosting under the p31labs org
Zenodo
Open-access research hosting (DOIs)
Stripe
Donation payment processing
Ko-fi
Donation / subscription processing
PayPal
Donation payment processing
Blockonomics
Cryptocurrency donation processing

The honest scope

P31 has not obtained SOC 2 or ISO 27001 certification. This page documents the controls that are in place. Known trade-offs are stated rather than hidden: the CSP uses 'unsafe-inline' for Astro's inline hydration scripts (a nonce pipeline is a P2 improvement), and the passkey worker returns Access-Control-Allow-Origin: * by design — WebAuthn trusts the rpId, not CORS.

Machine-readable disclosure: .well-known/security.txt.