Trust · our own front door
We audit other people's tenants. Here's our own posture.
A security practice that ships a sloppy website is telling you something. Every claim below is verifiable from your own terminal in under a minute — we'd encourage you to check.
Transport security
TLS-only behind Cloudflare; plain HTTP gets a permanent redirect, and HSTS (1-year, includeSubDomains) tells browsers never to try an insecure connection again.curl -sI https://cyber-risk-services.com/ | grep -i strict
Response headers
Every page ships CSP (frame-ancestors 'none'), X-Frame-Options: DENY, nosniff, a strict-origin Referrer-Policy, and a Permissions-Policy disabling camera, mic, and geolocation. Grade it at securityheaders.com.
Email authentication
Locked down the way we lock down client domains: SPF hard-fail (-all), DKIM via Microsoft 365, and DMARC quarantine with strict alignment. Mail that claims to be us and fails these isn't us.nslookup -type=TXT _dmarc.cyber-risk-services.com
Attack surface
Static HTML — no server code, database, login, forms, or first-party cookies. Nothing to inject into, no session to steal. The one third-party script (analytics, disclosed in our privacy notice) is the entire supply chain, and the CSP pins where it may talk.
Vulnerability disclosure
We publish an RFC 9116 security.txt. Find a weakness in anything we run, mail the principal — not a queue, same-business-day human reply. Good-faith research is never met with legal threats.
Engagement data
Client evidence is handled to the standard we advertise: SHA-512 sealed case folders with an independent verification script, so your counsel can prove the evidence hasn't changed since collection — without trusting us.
Want your tenant held to this standard? That's the tenant-hygiene engagement.