Trust and Security

This portfolio uses privacy-first defaults, strict security headers, and minimal data collection.

Last updated: 2026-09-20

Data collected

Only contact-form submissions are intentionally collected when you choose to send a message. No user account system or application database is used on this site.

Security controls

HTTP security headers, strict transport security, per-request script nonces, request validation, origin controls, and rate limiting are applied at the app and request-proxy layers.

Contact form handling

Contact form submissions pass through anti-spam checks and are forwarded to configured delivery targets (webhook or email provider). Sensitive secrets are stored in Vercel environment variables.

Operational hygiene

Platform credentials use unique passwords and multi-factor authentication. Dependencies and deployment settings are periodically reviewed for updates.

Security questions

Need implementation specifics for your security review?