Security
Public proof without production evidence.
The public site demonstrates product behavior while deliberately avoiding production-network evidence ingestion.
Public boundary
The public site is a low-trust demonstration and intake surface. Do not submit credentials, PHI, packet captures, production configuration, secrets, private keys, confidential customer evidence, or regulated records.
Deployment model
The reference deployment uses Nginx, restrictive security headers, a localhost-only Python service, rate-limited API endpoints, local SQLite storage, a dedicated unprivileged service account, and first-party cookie-free event collection.
Private product direction
Customer-specific evidence handling requires explicit identity, role-based access control, encryption, retention, audit, provenance, environment classification, and data-handling controls before ingestion. Those are product requirements, not implied capabilities of the public site.
Vulnerability reports
Send responsible security reports to info@bradfordinformatics.com. Do not include exploit details in the public contact form.