Crawler and bot policy
Which automated clients are allowed, which are challenged, which are blocked, and why the site does not use User-Agent as a security boundary.
How this site and the systems behind it are secured: headers, transport, secrets, dependencies, monitoring and disclosure.
HTTPS everywhere, TLS 1.2 minimum with TLS 1.3 preferred, HSTS with a one-year max-age, includeSubDomains and preload. HTTP is redirected, never served.
Content-Security-Policy restricting scripts, styles, fonts, connections and frames to an explicit allow-list. X-Content-Type-Options: nosniff. Referrer-Policy: strict-origin-when-cross-origin. X-Frame-Options: DENY and frame-ancestors none. Permissions-Policy denying the sensor and payment APIs the site does not use. Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy set to isolate the origin.
No secret is committed. Runtime secrets are Cloudflare Worker secrets, injected at the edge and never readable from a deployment log. The repository is scanned for accidentally committed credentials on every push.
Encrypted in transit by TLS and at rest by the storage platform. Personal information collected through the site is limited to what a form genuinely needs, retained on a stated schedule, and deleted on request.
Report a vulnerability to [email protected]. The machine-readable policy is at /.well-known/security.txt. We acknowledge within two business days, we do not threaten researchers who act in good faith, and we pay for findings through the public bounty board.
Where this page states a standard, an obligation or a research result, this is what it is drawn from. All external, all checkable.
Which automated clients are allowed, which are challenged, which are blocked, and why the site does not use User-Agent as a security boundary.
The public HTTP API behind the site: endpoints, versioning, rate limits, authentication and error format. Machine-readable schema at /openapi.json.
The canonical name, description, logo, domains and social handles. Use these verbatim in directories, articles and structured data.
Last reviewed · Site changelog