Auditable by design

Site security and privacy

THOR-SEC is a static site with a deliberately small attack surface. Everything below is enforced in the public source and checked on every change.

What the site enforces

  • Runtime surface

    Nothing runs in your browser

    • No JavaScript, cookies, or analytics.
    • One plain research-request form, on the commission page only. It accepts no uploads and records no IP address, browser details, or cookies.
    • No third-party fonts, scripts, or runtime assets.
    • Same-origin CSS and images only.
    • Light and dark themes follow your device setting. No preference is stored.
  • Browser policy

    Deny by default

    • Content Security Policy blocks scripts, frames, workers, objects, and network connections, and allows form submission only from the commission page, to the request endpoint and back to this site for the confirmation page.
    • Remote images and styles are blocked.
    • Referrer policy is no-referrer.
  • Deployment gates

    Checked before publish

    • A static security audit runs on every push to main and every pull request targeting main.
    • It checks links, duplicate IDs, active content, inline handlers and styles, insecure URLs, XML validity, and security metadata.
    • The workflow runs with read-only permissions and a commit-pinned checkout action.
  • Disclosure

    Report an issue

Hosting boundary: the site is served by GitHub Pages. Research requests are received by a single validating endpoint on the Cloudflare mirror and stored privately. Repository content enforces in-document browser controls and CI policy but cannot set every HTTP response header the host sends. External links leave the THOR-SEC boundary.