Observatory

Project method and boundary

Security

The platform treats official source content as hostile and keeps its public deployment static.

Fixed source clients

Clients use allowlisted HTTPS origins and paths, exact schemas, bounded pages and bytes, strict timeouts, redirect validation, and explicit content types.

Safe publication

Text is escaped, URLs are validated, privacy audits run at multiple boundaries, and the site uses a restrictive content security policy and no-referrer behavior.

No submission surface

There is no public form, victim search, breach-letter retrieval, runtime database, or application server.