SECURITY
Security and responsible disclosure
A plain-language baseline for the website. Legal counsel should review and finalize this page before public production launch.
Security posture
The public site is designed to minimize dependencies, load assets locally, validate and sanitize form inputs, use nonce protection, rate-limit submissions, and apply conservative browser security headers.
Reporting a vulnerability
Before launch, publish a dedicated security contact and security.txt file. Reports should include reproduction steps, affected URLs, impact, and a safe contact method.
Scope boundaries
Do not test production systems, access data, disrupt services, use automated exploitation, or disclose a suspected issue publicly without written authorization.
Product security claims
SANDA security capabilities remain subject to implementation, testing, and independent review. Website language must not be interpreted as a certification or guarantee.
Recommended launch controls
Use managed WordPress hosting, current PHP and WordPress versions, multi-factor authentication, least-privilege accounts, a web application firewall, daily backups, uptime monitoring, and a staged update process.