This project holds no certification of any kind, and this page is a factual description of what happens here — not a legal opinion, and not a claim of compliance with anything. It exists because a security probe asked for it by name and got a 404, and a 404 tells you nothing at all.
| Usually asked for | Here |
|---|---|
| SOC 2 Type I / II | Not held. No audit has ever been performed. What exists instead: the whole stack is static files behind a worker, described at /security. |
| ISO/IEC 27001 | Not held. There is no organisation to certify. |
| Penetration test report | None. No test has been commissioned. The attack surface is published instead: no origin server, no runtime, no database in a request path, no accounts, no forms. |
| Data processing agreement | Cannot be signed. There is no legal entity to be a party to one. What is processed is listed in /privacy.json. |
| Subprocessor list | Cloudflare, and nobody else — worker, static assets and the request-log database. |
| Vendor security questionnaire | Not answered individually. Every answer this project has is already on /security, /trust and /privacy.html, in public, for everyone. |
| Uptime SLA | None. Free-tier hosting, best effort, no guarantee. |
| Cyber insurance | None. |
What is processed, and nothing else: the request itself. Time, path, query string, user-agent, referer, accept header, status, bytes served, and a salted SHA-256 hash of the requesting address, truncated to 16 hex characters. The raw address is never stored and never served. The purpose is measuring who reaches this host; the aggregate result is public at /stats.json and the raw rows sit behind a token precisely because they carry other visitors' user-agents and address hashes. No automatic deletion is configured today — /privacy.html states that plainly instead of implying a schedule that does not exist. There are no accounts, so there is no profile to export or erase; requests for removal of a published client page are honoured, and that is the one piece of this a person can ask to have taken down.
None are set and none are read, by anything here. There is no consent banner because there is nothing to consent to, no JavaScript on any page, no tag manager and no third-party script. The pages work with scripting disabled entirely.
Plain semantic HTML, one stylesheet, no scripts, no images that carry meaning, no colour- only signals, and every page usable at any width and by a text browser. The machine-readable copy of nearly every page is linked from it, which is also the most accessible form there is. No formal audit (WCAG or otherwise) has been performed; see the first line of this page.
Everything here is CC0-1.0 — public domain, no attribution required, commercial use fine, mirroring encouraged. If your compliance question is "may we use this in a product", the answer is yes, without asking. /legal has the detail.
Nothing is sold, no payment is taken, no account is created, no software is distributed from this host under an export-controlled licence, and there is no age-gated content. The packages on /packages.html are published to public registries under their own licences.
/trust — what can be verified from outside in three curl commands · /security — the posture, and every probe path that is 404 on purpose · /privacy.html — the log, in full · /contact — one email address and what it is for.
Asked for by Mozilla/5.0 (compatible; apievangelist-security-probe/1.0)
at 2026-09-01T11:59:36Z in the same second as /trust and /security.
All three now answer.