IAPont / Guides and resources

Security without overpromising.

IAPont documents HTTPS, HSTS, security headers, the reporting channel and the limits of available verification.

HTTPS transport

Production configuration forces HTTPS and emits HSTS with includeSubDomains and preload. Correct configuration does not mean the domain is already included in every browser preload list.

Application headers

The application keeps a restrictive CSP, blocks framing, limits permissions and keeps CORS closed by default. These protections must be verified on responses actually served after deployment.

Report a vulnerability

security.txt points to this page. To send a report, use Koperateur Consulting contact, provide minimal reproduction steps and do not publish sensitive data.

Scope of checks

An external score, local test or absence of an alert is not proof of overall security. Limits and results are documented separately.

Version 1.8.4 candidate: review the test report before deployment.