Security

Security is not a slogan. It is a verifiable implementation task.

We describe confirmed controls precisely and avoid unsupported certification, availability or compliance claims.

Website and lead security

ASSETS

Local assets

Product media are served locally; no external font CDN is used.

CONSENT

Consent-based analytics

Google Analytics loads only after active consent.

INPUT

Server-side validation

Forms are validated on the server and protected against header injection.

BOT

Layered bot protection

Honeypot, CSRF, timing checks, rate limits, duplicate detection and optional Turnstile.

STORAGE

Protected lead storage

Lead data is stored in protected server-side storage and is not passed to analytics.

RETENTION

Controlled retention

A server-side purge routine supports defined deletion periods.

Product security information

Hosting location, encryption, backups, role models, logging, deletion concepts and availability must be confirmed against the production environment before publication as contractual claims.

No invented assurances

The website deliberately avoids phrases such as “100% secure”, “fully court-proof” or “guaranteed availability”.

Responsible disclosure

Security-related observations can be sent to frank@schadennetzwerk.com. The package also contains a security.txt file for technical contact discovery.

LoginBook demo