IAPont / Guides and resources
Security without overpromising.
IAPont documents HTTPS, HSTS, security headers, the reporting channel and the limits of available verification.
HTTPS transport
Production configuration forces HTTPS and emits HSTS with includeSubDomains and preload. Correct configuration does not mean the domain is already included in every browser preload list.
Application headers
The application keeps a restrictive CSP, blocks framing, limits permissions and keeps CORS closed by default. These protections must be verified on responses actually served after deployment.
Report a vulnerability
security.txt points to this page. To send a report, use Koperateur Consulting contact, provide minimal reproduction steps and do not publish sensitive data.
Scope of checks
An external score, local test or absence of an alert is not proof of overall security. Limits and results are documented separately.
Version 1.8.4 candidate: review the test report before deployment.