Security

Public-site security

Security controls currently visible in the Algogen marketing build, including HTTPS deployment, server-side rendering, CSRF checks, and server-held secrets.

Current public-site controls

  • The production site is served over HTTPS from one canonical origin.
  • Marketing and blog pages are rendered on the server.
  • The newsletter form checks a request token before accepting an email address.
  • Mailchimp and database credentials stay in server environment configuration and are not sent to the browser.

Current scope

This page describes the public marketing build. It is not a claim of certification, a penetration-test report, or a complete security statement for authenticated product access.

A dedicated vulnerability-reporting contact and authenticated-product security statement must be published before product access reopens.