Security & Privacy
Website Security
I take website security seriously and implement various measures to protect both my website and its visitors. This page outlines the security practices and technologies used on this site.
As a student learning about cybersecurity, I’m committed to implementing best practices and continuously improving the security posture of this website.
Security Measures
HTTPS Encryption
All communication between your browser and this website is encrypted using TLS/SSL protocols, ensuring that data transmitted remains confidential and secure.
Content Security Policy
The site implements Content Security Policy headers to prevent cross-site scripting (XSS) and other code injection attacks.
Secure Headers
Additional security headers are implemented to protect against common web vulnerabilities and enhance overall security posture.
Netlify Hosting Security
This website is hosted on Netlify, which provides built-in DDoS protection, automated security updates, and global CDN distribution for enhanced security and performance.
Data Privacy
This website respects your privacy and follows data protection principles. The site collects minimal data necessary for functionality and analytics.
For detailed information about data collection, usage, and your rights, please refer to the Privacy Policy.
Analytics & Tracking
This website uses Umami Analytics, a privacy-focused analytics platform that:
- Does not use cookies
- Does not track users across websites
- Respects Do Not Track browser settings
- Collects only aggregated, anonymized data
The analytics help me understand how visitors interact with the site to improve content and user experience while respecting privacy.
Contact Form Security
The contact form is protected against spam and abuse through multiple layers of security measures:
- IP-based rate limiting (5 requests per 15 minutes)
- Strict CORS policy with specific allowed origins
- Input validation and sanitization
- Form submission timing validation
- Structured security event logging
- Additional security headers (X-Content-Type-Options, X-Frame-Options, X-XSS-Protection)
- Secure email transmission with retry logic
- No storage of sensitive personal data
All contact form submissions are logged with security events for monitoring and analysis.
API Security
The website APIs implement robust security measures to protect against common web vulnerabilities:
- Strict CORS policies with domain-specific origins
- Rate limiting to prevent abuse and DDoS attacks
- Input validation and sanitization
- Security headers for all API responses
- Structured logging for security monitoring
- Proper error handling without information disclosure
Security Philosophy
”Security is not just about technology—it’s about building trust with users through transparent practices, continuous learning, and responsible data handling. As I grow in my cybersecurity journey, I’m committed to implementing security measures that protect both the website and its visitors.”
Reporting Security Issues
If you discover a security vulnerability on this website, please contact me through the contact form. I appreciate responsible disclosure and will address any legitimate security concerns promptly.