Public website controls
The web project uses security headers, a restrictive CSP, no third-party scripts by default and no client-side secrets.
Security
Shield documents security controls plainly and avoids publishing internal attack detail or unsupported guarantees.
Details
The web project uses security headers, a restrictive CSP, no third-party scripts by default and no client-side secrets.
Decision APIs should be called from trusted servers. Webhook signatures, key rotation and environment separation are part of integration hygiene.
This site does not claim certification, complete compliance, immunity to compromise, bank approval or measured uptime without independent evidence.