Skip to content

Security

How this website is built and defended, what Anquin does not claim, and how to report a vulnerability if you find one.

How this site is built

These are properties of the site as it runs today, not a roadmap. Each one can be checked from outside.

What we do

  • Everything is served over HTTPS only, with HTTP Strict Transport Security.
  • A strict Content Security Policy goes out with every response, carrying a nonce minted fresh for that request. Inline script that we did not put there does not run.
  • The site loads no third party scripts, no tag manager, and no advertising code. The only measurement is Vercel Web Analytics and Speed Insights, both served from this domain rather than from a script host, so no request for them leaves anquin.com.
  • It sets no cookies of its own and stores nothing in your browser for tracking. The measurement above is cookieless, which is why the site still asks you to accept nothing.
  • Security headers are generated from one file and verified against the deployed site, so what is configured and what is actually served cannot drift apart.
  • Any external origin the site depends on must be entered in a single registry before the policy will allow it, which makes adding a third party and widening the policy the same reviewable change.
  • Dependencies are pinned to exact versions and deliberately few. The site runs on five: the framework, the two React packages it needs, and the two measurement packages.
  • Access to the systems behind the site is limited to the people who need it.

What we do not claim

  • Anquin holds no SOC 2 report, no ISO 27001 certification, and no other security certification.
  • No external penetration test has been carried out on this site.
  • We are not certified or assessed under HIPAA, PCI DSS, or any similar regime, and we do not handle the kinds of data those cover.
  • We do not run a paid bug bounty.

If any of that changes, this page changes with it. Until then, take the absence of a claim as the claim.

Scope

This policy covers the Anquin corporate website and its subdomains.

In scope

  • This website and any subdomain of it.
  • The contact form and any endpoint it calls.
  • Security headers, transport configuration, and DNS records belonging to this domain.

Out of scope

  • The products operated by Anquin, which are separate services on separate domains and have their own disclosure processes.
  • Findings from automated scanners without a demonstrated impact.
  • Missing headers or configuration hardening with no exploitable consequence.
  • Denial of service, volumetric testing, and social engineering of staff.
  • Reports about software versions alone, absent a working proof of concept.

How to report

Email us. Please include enough detail to reproduce the issue: the affected URL, the steps you took, and what you observed.

If a report contains sensitive detail, say so and we will arrange an encrypted channel before you send it.

Send reports to

contact@anquin.com

What we ask

  • Give us reasonable time to investigate and fix before disclosing publicly.
  • Use only accounts and data that belong to you.
  • Do not access, modify, or delete data belonging to anyone else.
  • Stop at the point where you have demonstrated the issue, and do not pivot further.

What to expect

Acknowledgement
We aim to confirm receipt within three working days.
Assessment
We aim to give an initial assessment, including whether we consider the report in scope, within ten working days.
Progress
We will keep you informed while we work on a fix, and tell you when it is deployed.
Credit
We are glad to credit you when the issue is resolved, if you would like that. Tell us how you wish to be named.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will treat your activity as authorised. We will not pursue or support legal action against you in relation to it, and if a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorised.

Good faith means following the scope and the requests above. Activity that damages systems, degrades service for others, or accesses data belonging to third parties falls outside this protection.

Rewards

Anquin does not currently operate a paid bug bounty. Reports are still welcome and are taken seriously.