Home/ Security
Security posture

Security, practiced on ourselves first.

We sell exposure reduction. This page is the evidence. Most of the controls below can be verified from your own browser.

At a glance

The short version.

Four controls, satisfied today. Each is stated plainly and, where the browser allows, verifiable below.

  • Strict, static Content-Security-Policy. No inline script.
  • HSTS preloaded in Chromium. One-year max-age.
  • Every form gated by Turnstile. No third-party trackers.
  • Security reports acknowledged within 72 hours.
Verifiable

Do not take our word for it.

The response headers for this page are fetched live, in your browser, and printed below. What you read is what the server sent — not a screenshot, not a claim. Point the same instrument at any domain. Every first-party script and stylesheet is integrity-pinned with sha384; Cloudflare Turnstile is the single deliberate exception because its rotating challenge script cannot carry SRI, the one Observatory test we concede.

Verified live in your browser

Re-fetching this page to read its live response headers…

Scan a domain

Controls

Every layer, on the record.

Active implementations across six layers. Each is stated plainly and, where the browser allows, verifiable.

Edge
Strict static CSP, universal security headers, WAF.
Transport
TLS 1.3 only. 1.2 and below are refused. A+ target across transport and header posture checks.
Forms
Turnstile verification. No free-text bodies stored in plaintext.
Audit
Request logging with PII redacted at write time. 30-day retention.
Secrets
Vaulted. Never committed to source.
Telemetry
CSP-violation reporting and Network Error Logging to first-party endpoints.
Email & DNS

The layer most sites forget.

Spoofing starts where the domain is weakest. Ours is hardened in the open: DMARC at p=quarantine, SPF softfail (~all), DKIM signing, DNSSEC, and CAA records that pin who may issue our certificates.

Maintenance

A posture is a practice, not a milestone.

Recent hardening: strict CSP with violation reporting, universal security headers, Network Error Logging, and live header verification. The work is reviewed and extended. It does not finish.

Frameworks

Standards, not theatre.

We operate against published standards and map every engagement to them. No certifications are claimed here we do not hold.

NIST CSF 2.0
Default control taxonomy.
CIS Controls v8
Implementation Groups 1 through 3.
CyberSecure Canada
13-control baseline.
PIPEDA · Quebec Law 25 · PHIPA
Canadian privacy law, by jurisdiction.
Disclosure

Report a vulnerability.

Email security@redactlabs.ca. We acknowledge within 72 hours and target 30 days to remediate high-severity findings. Test in good faith, stay in scope, and give us time to fix before disclosure. This is the canonical Policy target of our /.well-known/security.txt.

72 h
Acknowledge
30 d
High-severity fix target
security@redactlabs.ca
Report to

Report a vulnerability

Acknowledgments

Credit, where it is earned.

Researchers are named here, with permission, once a report is validated and resolved.

No acknowledgments yet. No bug bounty at this time — security@redactlabs.ca.

Disclosure FAQ

Disclosure, answered.

How do I report?

Email security@redactlabs.ca.

Is there a bounty?

No bug bounty at this time. Valid reports receive acknowledgment and, with permission, public credit.

What is in scope?

redactlabs.ca and the services we operate.

Which frameworks govern this?

NIST CSF 2.0 and CIS Controls v8.

What do you log, and for how long?

Request logs with PII redacted, 30-day retention.

What about analytics?

No third-party analytics, no cookies, and no fingerprinting. Measurement is first-party and PII-free: coarse server-side pageview counts (path, country, browser class — never your IP or full user agent) plus first-party interaction events (which buttons and links are used, no per-visitor identifier). Both are recorded in our own Cloudflare Analytics Engine and shared with no analytics vendor. See our privacy policy for the full disclosure.

Engage

The same controls, on your domain.

Every control on this page is one we deploy for clients — security-first builds, hardened hosting, and retrofits for sites already in production. Scoped in writing, fixed-fee.