1. Principles
- Least privilege and need-based access.
- Separation of secrets from source code.
- Reduction of exposed surface area and unnecessary dependencies.
- Defense in depth and validation at trust boundaries.
- Logging and observability proportional to system risk.
2. Web security
The site uses HTTPS and security headers intended to reduce clickjacking, MIME sniffing, unnecessary browser capabilities and unauthorized resource loading. Content Security Policy restricts allowed origins while preserving legitimate functionality.
3. Data and secrets
Production credentials, API keys and secrets should not be stored in public repositories or exposed in interfaces. Projects should use environment variables, secret stores or other mechanisms appropriate to their infrastructure.
4. Authentication and authorization
Products requiring identity should apply authentication, session controls and authorization by resource or organization. Exact controls depend on the product and implementation agreement.
5. Dependencies and changes
We use version control and automated validation where included in the project workflow. Dependencies are reviewed and updated according to severity, compatibility and risk. Material changes should pass technical review and testing before production where the project flow supports it.
6. Availability, backups and recovery
Backup, recovery and continuity strategies depend on each product, infrastructure provider and agreement. We do not claim a specific RPO, RTO or redundancy level unless documented for the relevant service.
7. Incident response
For a confirmed incident, we prioritize containment, reasonable preservation of evidence, impact assessment, remediation and communication to affected parties when legally or contractually required.
8. Responsible disclosure
If you identify a vulnerability, send a reproducible description, estimated impact and minimal steps to the published contact. Do not access other people's data, establish persistence, disrupt services or publicly disclose a finding before we have a reasonable opportunity to investigate and remediate it.
9. Certifications and claims
PLAN0101 does not display security or compliance certifications on this site unless they have been formally obtained. Product-specific contractual or technical controls are documented separately.