Auditable by design
Site security and privacy
THOR-SEC is a static site with a deliberately small attack surface. Everything below is enforced in the public source and checked on every change.
What the site enforces
-
Runtime surface
Nothing runs in your browser
- No JavaScript, cookies, or analytics.
- One plain research-request form, on the commission page only. It accepts no uploads and records no IP address, browser details, or cookies.
- No third-party fonts, scripts, or runtime assets.
- Same-origin CSS and images only.
- Light and dark themes follow your device setting. No preference is stored.
-
Browser policy
Deny by default
- Content Security Policy blocks scripts, frames, workers, objects, and network connections, and allows form submission only from the commission page, to the request endpoint and back to this site for the confirmation page.
- Remote images and styles are blocked.
- Referrer policy is
no-referrer.
-
Deployment gates
Checked before publish
- A static security audit runs on every push to main and every pull request targeting main.
- It checks links, duplicate IDs, active content, inline handlers and styles, insecure URLs, XML validity, and security metadata.
- The workflow runs with read-only permissions and a commit-pinned checkout action.
-
Disclosure
Report an issue
Hosting boundary: the site is served by GitHub Pages. Research requests are received by a single validating endpoint on the Cloudflare mirror and stored privately. Repository content enforces in-document browser controls and CI policy but cannot set every HTTP response header the host sends. External links leave the THOR-SEC boundary.