Security
Reporting an issue.
Please do not open a public issue for a suspected vulnerability. Report it privately first.
How to report
Use thecontact details on the professional website(opens in a new tab). Machine-readable details are at/.well-known/security.txt.
What is in scope
- Draft or confidential content exposed on the public site
- Unsafe publication files or misleading citation metadata
- Dependency or build-workflow compromise
- A Content-Security-Policy bypass
- Domain, deployment, or cross-site link misconfiguration
What this site rules out by design
This is a static site with no authentication, database, public form, upload path, or runtime API. There is no server-side code to exploit and no write path a visitor can reach. The build refuses to produce a page containing a<form>, and the Content-Security-Policy setsform-action 'none', so that property is enforced rather than assumed.
Please do not run automated scanners against it. There is no application surface to test, and the traffic is indistinguishable from an attack in the logs.
How changes reach production
Production deploys only from the main branch. Each release is run through the full check suite before it reaches that branch: the build, type checks, unit tests, the generated-site and Content-Security-Policy contracts, and browser and accessibility tests. Recovery is a commit revert or promotion of the previous known-good deployment.