This page describes what the application does today. Where a control is a vendor's, that is said. Where something is not in place, that is said too.
http:// requests to https:// and send HSTS (max-age=31536000; includeSubDomains). The redirect does not apply to localhost. A zone-level "Always Use HTTPS" setting is outside this repository. The first request can still arrive over HTTP; the Worker answers that request with a redirect and does not send the page on it.copywriter-db). Voice-document text is in R2 (copywriter-docs). Cloudflare's documentation says those products encrypt data at rest. This application does not add its own encryption of individual fields. A KV namespace named SESSIONS is bound and unused. This repository does not set a D1 jurisdiction, so a database region is not stated here.main, after typecheck and a production build. There is no second-person code review.Email security@ for a vulnerability report, or info@ for a questionnaire. If something on this page is not ready, the reply will say so.
Contact security@