Security
Public security posture
- This origin is static and read-only. No public runtime API is necessary.
- No authentication, cookies or browser storage are used on this origin.
- No third-party scripts are loaded by default.
- Content-Security-Policy is restrictive with narrowly scoped
connect-src,object-src 'none'andbase-uri 'none'. - Static configuration requests strict transport security, content-type sniffing protection, referrer policy and permissions policy; hosted-response verification remains outstanding.
- No source maps containing sensitive source or paths are published.
Separation from trading systems
Responsible disclosure
If you believe you have found a security vulnerability in this website or the SahaFX research programme, please report it responsibly. Do not publish details publicly before a remediation timeline has been agreed.
Reports may be submitted through the published email channel on davidtheuri.com — include “Security report” in the subject. Include a description of the issue and reproduction steps. Do not send credentials or sensitive personal data.
Security headers
The following headers are tested on each deployed origin. Configuration presence is insufficient; values are verified against the live response.
Content-Security-PolicyStrict-Transport-SecurityX-Content-Type-Options: nosniffReferrer-PolicyPermissions-PolicyCross-Origin-Opener-Policy- CSP
frame-ancestorsrestriction