Security of this site and of our practice
We ask manufacturers to evidence their security. It would be poor form not to evidence our own.
This website
- Static, no CMS, no database, no server-side code. There is nothing to log into and nothing to inject into.
- No third-party scripts, no analytics, no advertising, no embedded fonts from a CDN. Fonts are self-hosted. Consequently we set no cookies and show no cookie banner, because there is nothing to consent to.
- Content Security Policy, HSTS, X-Content-Type-Options, Referrer-Policy and a restrictive
Permissions-Policy are set at the edge. See
/_headersin the deployment. - TLS only. HTTP redirects to HTTPS; certificates are logged in Certificate Transparency and can be inspected by anyone.
Reporting a vulnerability
If you find a security issue in this site or in anything we operate, tell us. We will not take legal action against good-faith research that respects the boundaries below.
| Item | Detail |
|---|---|
| Contact | security@veltra-security.com |
| Machine-readable policy | /.well-known/security.txt |
| Acknowledgement | Within 2 working days |
| Assessment | Within 10 working days |
| Disclosure | Coordinated. We will agree a date with you and credit you unless you prefer otherwise. |
Out of scope
Denial of service, social engineering of our people or suppliers, physical attacks, automated scanner output with no demonstrated impact, and anything that would access another party's data.
Client work
- Client data stays segregated. Each engagement has its own storage, its own credentials and its own retention clock.
- Findings are never published. Any example on this site is illustrative and invented.
- No commission from a vendor we assess. Our go-to-market practice is a separate engagement type with a separate client list. A vendor we advise commercially is never a vendor whose product we evaluate in a client's technical file, and the wall is stated in writing in both contracts.