SECURITY / THIS WEBSITE

What this site is made of, and what it cannot reach.

This covers the pages served at hmcortex.com. How an account is kept is a different question about a different system, answered by the policy that system publishes and linked below rather than summarised here.

01 / WHAT IT IS MADE OF

Files on a host, and nothing running.

Every page here is built ahead of time and served as a file. There is no application behind them, no database, and no session. There is nothing to sign in to and no field to type a credential into, so there is no credential for a page of this site to mishandle.

One page has a form on it, and it is handled the way the pages are. A submission goes to the host that serves them, which was built to take one; nothing written in this repository runs to receive it, and there is no store on this side for it to be written to. What it asks for and where it ends up is on the contact page, and what that means for you is on the privacy notice.

The one address a page sends you to is the account surface, and it is a link like any other: this site carries no sign-in form, holds no session, and shows no signed-in view.

02 / WHAT IT CANNOT REACH

Your machine, and everything on it.

hm runs where you run it, against folders you point it at. Nothing on this site can open one, list one, or ask a browser to look — a page of static markup has no way to, and there is no part of hm running on this address that could be asked. The same is true of the account surface, which is why the privacy notice can say what it says.

03 / THE CANONICAL POLICY

How an account is kept is written where it is true.

Sign-in, sessions, what a page there is allowed to load, and what has not been built yet — all of it is stated on the account surface's own policy, under the rule that every technical claim on it is one its code makes true and its tests hold to. A second copy on this site could not be held to anything, so there is not one.

04 / REPORTING SOMETHING

There is one route, and it is on that policy.

The policy linked above names the address to write to, what to expect back, and the terms a report is read under. That address is not repeated here on purpose: two places to send a vulnerability is one place that eventually stops being read.

Anything about these pages rather than about a report goes to the contact page. If you cannot reach it, ask whoever pointed you at this page.

05 / WHAT IS NOT CLAIMED

No certification, and no audit.

There is no third-party attestation of any kind behind hm today, and no page here will carry a badge suggesting one. Where that changes it will be said on the policy above, which is the document that could be held to it.