Skip to content
iOchronaSecurity Architect
PL
01

Website security

Website security

Public information about the contact form, technical logs, encrypted transport and the handling of first-contact data.

01

encrypted transport

02

limited first-contact data

03

short technical-log retention

04

updated: 7 August 2026

01

Technical standard

Safeguards matched to an information website and contact form.

Broader operational material is moved to an agreed channel after the matter has been qualified.

01

Design principles

The website is designed around a limited attack surface, data minimisation, encrypted transport, short log retention and controlled administrative access.

The application runs behind an Nginx reverse proxy. The public service is exposed through HTTPS, while the application listens only on the local server interface.

02

Contact form

The form validates fields, limits body size and request frequency and uses a hidden anti-spam field. The message is sent through a restricted mail API key.

The website does not ask for passwords, access codes or detailed operational material in the first message.

03

Logs and retention

Technical logs support security, diagnostics and continuity. The standard Nginx log-retention period is 7 dni. Form content is omitted from the server log.

Broader case material should be moved to an agreed channel after qualification.

04

Security headers and dependencies

The public response uses security headers including Content Security Policy, HSTS, clickjacking protection, MIME-type protection and a restrictive permissions policy.

Dependencies, server access, firewall rules, SSH configuration and provider access should be reviewed after material technical changes.

05

Responsible reporting

A technical security concern may be reported to iochrona@icloud.com. Include the affected page, date, approximate time and enough detail to reproduce the issue, without sending harmful payloads or unrelated personal data.