Security

Security without theatre

Practical controls, restrained claims and a direct route for responsible vulnerability reports.

01 / Data in transit

Protected public connections

Public production pages use HTTPS. Sensitive configuration and provider credentials are kept outside public client code and are supplied through controlled server-side configuration.

02 / Access control

Least access needed

Administrative surfaces are not treated as public content. Access is scoped to the person, service and environment that need it, with production permissions reviewed before launch.

03 / Logs and recovery

Evidence before assurance

Logging, backup and recovery expectations are defined per production service. We do not claim a control is active merely because it exists in a local build or design document.

04 / Responsible disclosure

Report a vulnerability

Send a concise description, affected URL and reproduction steps to security@tjnovaltd.com. Please avoid accessing unrelated data or disrupting services. Receipt and bounty payments are not guaranteed.