Security
Last updated
This page describes how priipfold.com is built and served, and how to tell us if you find something wrong with it. It states nothing you cannot check for yourself.
How the site is served
Every page here is a static file, built in advance and served as it stands. No application code runs to answer a request. This site carries no database, no sign-in and no upload, so there is nothing behind it to reach.
Hosting and delivery are Cloudflare's. That is the whole of the arrangement, and it is set out on the sub-processors page.
In transit
Pages are served over HTTPS, and the certificates are issued and renewed by the hosting provider. The zone is set to refuse anything below TLS 1.2, so a connection negotiated with TLS 1.0 or 1.1 does not complete. Your browser will tell you which version it actually used, in the same panel as everything else on this page.
What a page loads
Everything a page needs to render is served from this domain, the typefaces included. There is no tag manager, no font host and no advertising network in the path between you and the page, and nothing here sets a cookie.
One request does leave this domain, and it is the only one: a page-view counter, loaded from cdn.usefathom.com. It sets no cookie, writes nothing to your device and reports one thing — that a page was opened. What it processes, who runs it and how to decline it are set out on the privacy page. Your browser's network panel will show you this list in about ten seconds, and it should show you nothing on it that is not named here. If it does, that is worth telling us about, and the section below says how.
What the site holds
No personal data sits behind these pages: no account, no document, no figure, no file. The only personal data that reaches us by way of this site is what you choose to put in an email, and the page-view count described on the privacy page, which reaches us as totals rather than as rows about anybody.
Reporting a vulnerability
If you find a problem with this site, write to hello@priipfold.com. Put the word security in the subject line if it helps you; the message is read either way. Tell us what you found, what you did to find it, and what you think it lets someone do. A short proof of concept is worth more than a scanner report.
We acknowledge a report within five working days, and tell you what we make of it and what we intend to do about it. If we decide against acting on something, you will hear that from us as well, with the reason. We ask for a reasonable period before you describe it publicly, and we will ask for no silence beyond that. There is no bounty programme, and we would still rather hear from you than not.
Anything you can do with a browser and its developer tools is fair. Automated scanning at a rate that degrades the site for other people is not. On a set of static files a scanner has little to find, and its output is rarely something anyone can act on.