Security
Our security posture
- All pages served over HTTPS with HSTS
- Strict Content Security Policy headers
- No server-side storage of financial inputs (client-only architecture)
- Input validation with Zod
- Regular dependency updates via Renovate
- No authentication = no credential attack surface in Wave 1
Responsible disclosure
If you discover a security vulnerability, please disclose it responsibly. Email support.cosyslabs@gmail.com with subject "Security Vulnerability." We will respond within 72 hours.
See also: security.txt
Headers grade
Our security headers target grade A on securityheaders.com.