$
BBI

Security

Our security posture

  • All pages served over HTTPS with HSTS
  • Strict Content Security Policy headers
  • No server-side storage of financial inputs (client-only architecture)
  • Input validation with Zod
  • Regular dependency updates via Renovate
  • No authentication = no credential attack surface in Wave 1

Responsible disclosure

If you discover a security vulnerability, please disclose it responsibly. Email [email protected] with subject "Security Vulnerability." We will respond within 72 hours.

See also: security.txt

Headers grade

Our security headers target grade A on securityheaders.com.