Security / disclosure
Controls you can
inspect.
Security posture is described as testable behaviour—not as a certification claim.
Website controls
- HTTPS with HSTS, CSP, clickjacking, MIME-sniffing and restrictive permissions headers on HTML and API responses.
- Self-hosted fonts and no advertising scripts.
- Same-origin form submission, honeypot filtering, validation and per-email throttling.
- Aggregate first-party analytics without cookies, IP storage or cross-site identifiers.
- Persistent enquiries stored in the site database with bounded fields.
Client-system controls
Controls are selected per architecture: identity and least privilege, environment separation, secret management, versioned changes, evaluations, human approval, logs, incident workflow, backup and restore, supplier inventory and provider exit testing. A security matrix is part of the vendor pack for scoped work.
Responsible disclosure
Send a concise report to hello@n137.ai with the affected URL, impact and reproduction steps. Do not access other people’s data, degrade service or use social engineering. We will acknowledge credible reports and coordinate remediation.
Machine-readable contact: security.txt.
Current boundaries
The site is delivered through Cloudflare-backed infrastructure, which may set a bot-management cookie and process network metadata independently. N137.AI does not claim ISO 27001, SOC 2 or another certification unless a current report is supplied during diligence.