Policy
Security and Incident Response
How security incidents are detected, reported, and resolved — effective September 2026.
Infrastructure
This site runs on Cloudflare Workers with built-in DDoS protection, TLS encryption, and edge caching. All data in transit is encrypted via HTTPS. Durable Objects provide isolated, consistent storage.
Incident Detection
- Cloudflare analytics and security events are monitored
- AI safety counters track crisis detection and content screening events
- Support ticket patterns are reviewed for abuse signals
Incident Response
On detection of a security incident:
- Contain — isolate affected systems or features
- Assess — determine scope and data impact
- Remediate — patch, rotate credentials, restore from known-good state
- Notify — inform affected users if personal data was exposed
- Review — document lessons and update defenses
Reporting a Vulnerability
If you discover a security issue, report it through Owner Services on the homepage. Select the "Safety" category. Do not publicly disclose vulnerabilities before they are resolved.