Security, practiced on ourselves first.
We sell exposure reduction. This page is the evidence. Most of the controls below can be verified from your own browser.
The short version.
Four controls, satisfied today. Each is stated plainly and, where the browser allows, verifiable below.
- Strict, static Content-Security-Policy. No inline script.
- HSTS preloaded in Chromium. One-year max-age.
- Every form gated by Turnstile. No third-party trackers.
- Security reports acknowledged within 72 hours.
Do not take our word for it.
The response headers for this page are fetched live, in your browser, and printed below. What you read is what the server sent — not a screenshot, not a claim. Point the same instrument at any domain. Every first-party script and stylesheet is integrity-pinned with sha384; Cloudflare Turnstile is the single deliberate exception because its rotating challenge script cannot carry SRI, the one Observatory test we concede.
Verified live in your browser
Re-fetching this page to read its live response headers…
Every layer, on the record.
Active implementations across six layers. Each is stated plainly and, where the browser allows, verifiable.
- Edge
- Strict static CSP, universal security headers, WAF.
- Transport
- TLS 1.3 only. 1.2 and below are refused. A+ target across transport and header posture checks.
- Forms
- Turnstile verification. No free-text bodies stored in plaintext.
- Audit
- Request logging with PII redacted at write time. 30-day retention.
- Secrets
- Vaulted. Never committed to source.
- Telemetry
- CSP-violation reporting and Network Error Logging to first-party endpoints.
The layer most sites forget.
Spoofing starts where the domain is weakest. Ours is hardened in the open: DMARC at p=quarantine, SPF softfail (~all), DKIM signing, DNSSEC, and CAA records that pin who may issue our certificates.
A posture is a practice, not a milestone.
Recent hardening: strict CSP with violation reporting, universal security headers, Network Error Logging, and live header verification. The work is reviewed and extended. It does not finish.
Standards, not theatre.
We operate against published standards and map every engagement to them. No certifications are claimed here we do not hold.
- NIST CSF 2.0
- Default control taxonomy.
- CIS Controls v8
- Implementation Groups 1 through 3.
- CyberSecure Canada
- 13-control baseline.
- PIPEDA · Quebec Law 25 · PHIPA
- Canadian privacy law, by jurisdiction.
Report a vulnerability.
Email security@redactlabs.ca. We acknowledge within 72 hours and target 30 days to remediate high-severity findings. Test in good faith, stay in scope, and give us time to fix before disclosure. This is the canonical Policy target of our /.well-known/security.txt.
- 72 h
- Acknowledge
- 30 d
- High-severity fix target
- security@redactlabs.ca
- Report to
Credit, where it is earned.
Researchers are named here, with permission, once a report is validated and resolved.
No acknowledgments yet. No bug bounty at this time — security@redactlabs.ca.
Disclosure, answered.
How do I report?
Email security@redactlabs.ca.
Is there a bounty?
No bug bounty at this time. Valid reports receive acknowledgment and, with permission, public credit.
What is in scope?
redactlabs.ca and the services we operate.
Which frameworks govern this?
NIST CSF 2.0 and CIS Controls v8.
What do you log, and for how long?
Request logs with PII redacted, 30-day retention.
What about analytics?
No third-party analytics, no cookies, and no fingerprinting. Measurement is first-party and PII-free: coarse server-side pageview counts (path, country, browser class — never your IP or full user agent) plus first-party interaction events (which buttons and links are used, no per-visitor identifier). Both are recorded in our own Cloudflare Analytics Engine and shared with no analytics vendor. See our privacy policy for the full disclosure.
The same controls, on your domain.
Every control on this page is one we deploy for clients — security-first builds, hardened hosting, and retrofits for sites already in production. Scoped in writing, fixed-fee.