Security
Reporting a vulnerability
If you have found a security issue affecting this site or the platform it describes, report it to henri@iamrain.ai. We ask that you give us reasonable time to investigate and address a report before any public disclosure.
A machine readable disclosure route is published at /.well-known/security.txt.
This site
- Served over HTTPS with HSTS enabled.
- Content Security Policy, X-Content-Type-Options, Referrer-Policy and Permissions-Policy headers applied to every response.
- No third party trackers beyond cookieless analytics. No chat widgets. No marketing pixels.
- Form submissions are validated server side.
The platform
Identity and access on the platform is Keycloak based and Kubernetes native. It applies least privilege by default. See Standards and connectors for the identity and access model. See Sovereign deployment for data control and deployment posture.