Protected public connections
Public production pages use HTTPS. Sensitive configuration and provider credentials are kept outside public client code and are supplied through controlled server-side configuration.
Practical controls, restrained claims and a direct route for responsible vulnerability reports.
Public production pages use HTTPS. Sensitive configuration and provider credentials are kept outside public client code and are supplied through controlled server-side configuration.
Administrative surfaces are not treated as public content. Access is scoped to the person, service and environment that need it, with production permissions reviewed before launch.
Logging, backup and recovery expectations are defined per production service. We do not claim a control is active merely because it exists in a local build or design document.
Send a concise description, affected URL and reproduction steps to security@tjnovaltd.com. Please avoid accessing unrelated data or disrupting services. Receipt and bounty payments are not guaranteed.