Responsible disclosure and website security.
Calyvex is designed as a static website with a deliberately small public attack surface. Security reports are welcome, but testing still requires authorization.
Report a security issue
If you believe you found a vulnerability in the public Calyvex website, use the contact page and provide only the minimum information needed to establish contact. Do not include credentials, private keys, customer data or destructive proof-of-concept material.
Safe reporting boundaries
A report does not create authorization for intrusive testing. Do not perform denial-of-service activity, social engineering, credential attacks, persistence, destructive actions, data exfiltration or tests against third-party services.
Architecture
The public website is statically generated with Eleventy and deployed through GitHub Pages. Cloudflare is used for the public domain, delivery and security controls. Pages CMS writes approved content changes to the repository through GitHub authentication. The site does not require a custom application server or database for normal public browsing.
Security controls
The source package includes a restrictive Content Security Policy fallback, consent-controlled analytics, a honeypot and field limits on the contact form, dependency update automation, a security.txt file and deployment guidance for Cloudflare response security headers.
No security guarantee
No internet-facing service can truthfully be described as completely attack-free. The goal is to minimize exposed functionality, apply layered controls, monitor changes and respond quickly when a problem is discovered.