LAST UPDATED 2026-08-10
How this site is built and operated. Everything below is verifiable from the outside — check it rather than take our word for it.
Transport
Served over HTTPS only, with HTTP Strict Transport Security (max-age one year, includeSubDomains, preload) so browsers refuse an unencrypted connection.
DNSSEC
cryptaguard.com is signed with DNSSEC. A DS record is published at the parent zone and the responses carry RRSIG signatures, so a resolver can detect a forged answer. You can confirm this with: dig +dnssec cryptaguard.com
Browser hardening
A Content-Security-Policy restricts what the page may load and embed, X-Frame-Options blocks framing by other sites, and Referrer-Policy limits what is leaked when you follow an outbound link.
Secure by design
No advertising or cross-site tracking is present. Analytics stay off until you consent. External links open with rel="noopener", so a destination cannot manipulate the tab it came from. Dependencies are patched on a rolling basis and the build fails on a known high-severity advisory.
Data on this site
The site is a showcase; it holds no client data. The contact form does not transmit anything to us on its own — it opens your own mail client with the message ready to send, so you stay in control of what leaves your machine.
Reporting a vulnerability
If you find a weakness in this site, write to contact@cryptaguard.com with enough detail to reproduce it. We will acknowledge within two business days. Please give us reasonable time to fix it before publishing, and do not access data that is not yours while testing.