Trust · our own front door

We audit other people's tenants. Here's our own posture.

A security practice that ships a sloppy website is telling you something. Every claim below is verifiable from your own terminal in under a minute — we'd encourage you to check.

Transport security

TLS-only behind Cloudflare; plain HTTP gets a permanent redirect, and HSTS (1-year, includeSubDomains) tells browsers never to try an insecure connection again.
curl -sI https://cyber-risk-services.com/ | grep -i strict

Response headers

Every page ships CSP (frame-ancestors 'none'), X-Frame-Options: DENY, nosniff, a strict-origin Referrer-Policy, and a Permissions-Policy disabling camera, mic, and geolocation. Grade it at securityheaders.com.

Email authentication

Locked down the way we lock down client domains: SPF hard-fail (-all), DKIM via Microsoft 365, and DMARC quarantine with strict alignment. Mail that claims to be us and fails these isn't us.
nslookup -type=TXT _dmarc.cyber-risk-services.com

Attack surface

Static HTML — no server code, database, login, forms, or first-party cookies. Nothing to inject into, no session to steal. The one third-party script (analytics, disclosed in our privacy notice) is the entire supply chain, and the CSP pins where it may talk.

Vulnerability disclosure

We publish an RFC 9116 security.txt. Find a weakness in anything we run, mail the principal — not a queue, same-business-day human reply. Good-faith research is never met with legal threats.

Engagement data

Client evidence is handled to the standard we advertise: SHA-512 sealed case folders with an independent verification script, so your counsel can prove the evidence hasn't changed since collection — without trusting us.

Want your tenant held to this standard? That's the tenant-hygiene engagement.