Skip to content
Octopus Research Institute

Security

The site is built to a conservative security posture: minimal attack surface, no third-party code by default, and a clear channel to report problems.

This is draft content provided for transparency and requires legal review before it is relied upon.

Headers & policy

The site sets a strict Content-Security-Policy and security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and HSTS). It loads no third-party scripts, fonts or trackers by default.

Forms & uploads

Form input is validated server-side and protected by a honeypot and a per-IP rate limit. File upload is disabled, and no sensitive or research data should be submitted through public forms.

Secrets & accounts

No secrets are exposed in client code — only public configuration reaches the browser — and there are no user accounts in this phase.

Vulnerability disclosure

To report a vulnerability, contact the security address below. Please allow reasonable time for remediation before public disclosure.

security@octopusresearch.org

Research misuse

We weigh the misuse potential of any release and withhold detail where the risk outweighs the benefit.