Trust
Security
Last reviewed 29 August 2026
Mooseify.net has a deliberately small attack surface: mostly static company and product content, no public account system and one protected contact channel. A small website should still have a considered security posture.
Our approach
- controlled account and deployment access;
- HTTPS everywhere, with HSTS and browser security headers;
- no third-party scripts, analytics or tracking; web fonts served from our own server;
- server-side validation of contact submissions, with a honeypot field and rate limiting;
- restricted logging and data minimisation;
- dependency and deployment review, with an automated check suite on every change;
- an explicit route for reporting vulnerabilities.
This summary is not a certification or a guarantee that the website or any product is free from vulnerabilities.
Report a potential security issue
Email security@mooseify.net. Please include:
- the affected URL, domain or product;
- a clear description of the issue;
- steps that let us reproduce it safely;
- the potential impact;
- non-sensitive screenshots or request details where useful;
- a contact method for follow-up.
Do not send passwords, private keys, unrelated personal data, customer data or confidential documents. If sensitive evidence is genuinely necessary, ask us first to agree on a safer transfer method.
Responsible testing boundaries
A report does not authorise you to:
- access, change or download data that does not belong to you;
- disrupt service, exhaust resources or send high-volume traffic;
- use social engineering, phishing or physical attacks;
- test third-party services outside Mooseify’s control;
- install malware or persistence;
- publicly disclose an issue before reasonable coordination;
- demand payment or threaten disclosure.
Stop testing once you have enough information to demonstrate the issue safely.
What happens after a report
We review reports and respond when further information or coordination is relevant. We do not promise a specific response or remediation time, a bounty, or a legal safe harbour through this page. Where a report concerns MinaAvtal, Aura or another product, we may route it to the appropriate product owner and terms.
Information we do not publish
We do not publish detailed infrastructure diagrams, detection rules, secret-management procedures or other detail that would materially weaken security.
Contact-form security
The general Contact form is not the place for vulnerability details. Use security@mooseify.net so the report is handled separately.