Security

Security posture and disclosure policy

A practice that advises on cybersecurity should hold its own site to the same standard. Every control below is stated plainly and can be verified independently — you do not have to take our word for it.


Verifiable Posture

How this site is secured

Each item below is a control actually in place, paired with a way to confirm it yourself using independent, third-party tools.


Current Limitations

What this site does not yet enforce

Stating a posture accurately means stating its gaps. A public header scan of this site will show missing response headers. The reason is architectural, not an oversight.

This site is served by a static host that does not permit custom HTTP response headers. Several controls that are normally delivered as headers — HTTP Strict Transport Security, X-Frame-Options, X-Content-Type-Options, and Permissions-Policy — cannot be set under that constraint.

Content Security Policy and Referrer Policy are delivered through document metadata instead, which browsers honor for most directives. frame-ancestors is the notable exception: it is declared but is not enforced under meta-tag delivery.

Transport security is enforced at the TLS and DNS layers, both independently verifiable above. Header-based controls are pending a change in hosting architecture.

Not Currently Set

  • Strict-Transport-Security
  • X-Frame-Options
  • X-Content-Type-Options
  • Permissions-Policy

Delivered Via Metadata

  • Content-Security-Policy
  • Referrer-Policy

Coordinated Disclosure

Reporting a vulnerability

If you have identified a security vulnerability affecting sanctir.com, we welcome your report and will treat it seriously. Please send details — including steps to reproduce and any relevant technical context — to the security contact below.

We will acknowledge receipt and respond as promptly as circumstances allow. In the course of your research, we ask that you act in good faith: avoid privacy violations, service disruption, and any destruction or exfiltration of data.

A machine-readable policy is published at /.well-known/security.txt in accordance with RFC 9116.

Security Contact

Policy File

Scope

  • sanctir.com and subdomains
  • Email authentication for sanctir.com

Return to Sanctir