Site security
- HTTPS everywhere with HSTS
- Content Security Policy and hardened response headers
- Contact form protected by Cloudflare Turnstile, server-side validation and rate limiting
- Parameterized queries for all stored data
- No API secrets in client code; secrets live in Cloudflare environment configuration
- Automated dependency security scanning in CI
- Quarterly review of dependencies and security headers (OWASP Top 10 baseline)
Reporting
If you believe you have found a vulnerability in a RUR1 site or product, please contact us at sys@rur1.com. We respond to good-faith reports and credit reporters when a fix ships.