Skip to content
Security

Security posture

Runtime hardening

Helmet CSP, HSTS in production, CORS allow-listing, rate limits and body sanitization protect public APIs.

Secrets

GitHub Actions can sync secrets to Hetzner .env with masked values, SSH validation and PM2 reload. External provider secrets are optional until enabled.

Payments

Direct BTC owner-wallet checkout is the current production rail. NOWPayments uses HMAC IPN verification only when enabled later.

Integrity

The site publishes Ed25519-signed integrity at /.well-known/unicorn-integrity.json and DID discovery at /.well-known/did.json.

QuantumIntegrityShield

The backend exposes exact diagnostics at /api/quantum-integrity/status and avoids false degraded state from retired PM2 process names.

Incident handling

Incidents are sealed publicly and linked from /status and /trust.

Last updated: 2026-04-28 · Owner: Vladoi Ionut · Contact: vladoi_ionut@yahoo.com

build 3d1ef61897b2