Security / disclosure

Controls you can
inspect.

Security posture is described as testable behaviour—not as a certification claim.

Website controls

  • HTTPS with HSTS, CSP, clickjacking, MIME-sniffing and restrictive permissions headers on HTML and API responses.
  • Self-hosted fonts and no advertising scripts.
  • Same-origin form submission, honeypot filtering, validation and per-email throttling.
  • Aggregate first-party analytics without cookies, IP storage or cross-site identifiers.
  • Persistent enquiries stored in the site database with bounded fields.

Client-system controls

Controls are selected per architecture: identity and least privilege, environment separation, secret management, versioned changes, evaluations, human approval, logs, incident workflow, backup and restore, supplier inventory and provider exit testing. A security matrix is part of the vendor pack for scoped work.

Responsible disclosure

Send a concise report to hello@n137.ai with the affected URL, impact and reproduction steps. Do not access other people’s data, degrade service or use social engineering. We will acknowledge credible reports and coordinate remediation.

Machine-readable contact: security.txt.

Current boundaries

The site is delivered through Cloudflare-backed infrastructure, which may set a bot-management cookie and process network metadata independently. N137.AI does not claim ISO 27001, SOC 2 or another certification unless a current report is supplied during diligence.