Security
Updated on
This page explains what happens when you visit this site. You can check every claim below in your browser.
What this site keeps
Nothing. The only records are the host’s operational logs, described on the Privacy page. The site sets no cookie, opens no account, keeps no database and runs no analytics. There is therefore no profile, no persistent identifier and no browsing history to consult, export or delete.
Checking takes a minute. Open your browser’s developer tools, Network tab, then reload this page. No response sets a cookie. No requests are sent to third-party domains. Even the fonts are served from this domain.
Where the site is served
- Host
- Vercel Inc.
- Address
- 440 N Barranca Avenue #4133, Covina, CA 91723, United States
- Execution region
- Washington D.C., United States
All server-side processing happens in the region shown, outside the European Union. Static files are delivered from the point of presence nearest the visitor. As on any site, a visitor’s IP address is processed by the host for as long as it takes to compose the response.
Encryption
Traffic runs over HTTPS only. This site instructs the browser to use HTTPS and nothing else for two years, subdomains included.
What the browser is allowed to load
The site sends a policy with every page, and the browser enforces it itself. It forbids anything from loading from another domain. No script, stylesheet, font, image, frame or form may come from another site or send data to it. Plugins are refused. The site also refuses to appear inside another page. This prevents another site from overlaying it to hijack your clicks. The browser also refuses access to device features this site does not use. These include the camera, microphone, location, payments and sensors. These refusals would also apply to any content the site might embed one day.
One limitation remains. The policy refuses any script written into the page. For styles written into the page, the header sent with each response stays permissive, and a second policy, written into the page itself, accepts them only if they match a hash calculated at build time. The browser enforces both, and nothing can load from another domain.
Mozilla’s HTTP Observatory analyses the policy from outside. See the report for mohmak.com. The limitation described above keeps it from earning the full bonus there.
Reporting a vulnerability
- Write to contact@mohmak.com. We reply within two business days.
- Describe what you observed, how to reproduce it, and your assessment of the impact. A minimal demonstration is more useful than the output of an automated scanner.
The disclosure file published on this site lists the same address and its expiry date.
Safe harbour
Research carried out in good faith and within the rules below will not lead to legal action or a complaint from us. This commitment covers anyone who:
- stays within the domains we operate
- stops at demonstration and does not access, alter or retain anyone else’s data
- does not interrupt or degrade the service, and refrains from deliberate saturation
- uses neither social engineering, nor phishing, nor physical access
- gives us a reasonable amount of time before publishing any findings
No financial reward is paid.
What this site does not do
- It holds no security certification, and therefore displays none.
- It hosts no service status page. The status of a product belongs on that product’s domain.
- It accepts no file upload, and therefore stores no received file.
- It hosts no form. A project description goes through an external provider.
Write to the publisher
We reply within two business days, and we read this inbox ourselves.
Write to contact@mohmak.com