SECURITY
Security Information
Last updated: October 11, 2026
1. Safe use
Only download files you are authorized to access and from sources you trust. Verify file types, keep your device updated, and use reputable security software.
2. Do not publish sensitive files publicly
Files placed in a public web directory may be accessible to anyone who knows or discovers the URL. Use authenticated storage and access controls for private company documents or personal data.
3. Transport security
Configure a valid SSL/TLS certificate with your hosting provider and ensure HTTP redirects to HTTPS. A padlock encrypts the connection but does not by itself make files private or prove that a file is safe.
4. Report a vulnerability
Send a concise description and the affected URL to [INSERT MONITORED SECURITY EMAIL]. Do not access, modify, download, or disclose data that is not yours. Do not conduct disruptive testing without written authorization.
5. Before production
If you add file uploads or private sharing, consider authentication, least-privilege access, file size/type validation, malware scanning, rate limits, secure storage outside the public web root, logging, backups, retention limits, and a tested incident-response process.