Security

Security architecture, stated carefully

Shield documents security controls plainly and avoids publishing internal attack detail or unsupported guarantees.

Details

Clear claims, explicit boundaries

Public website controls

The web project uses security headers, a restrictive CSP, no third-party scripts by default and no client-side secrets.

Application controls

Decision APIs should be called from trusted servers. Webhook signatures, key rotation and environment separation are part of integration hygiene.

What is not claimed

This site does not claim certification, complete compliance, immunity to compromise, bank approval or measured uptime without independent evidence.