Security & Trust
Trust statements carry a status.
This register separates controls that are implemented on this website from practices that still require technical or contractual confirmation. Nothing here is a certification claim.
Corporate website
A minimal public data surface.
Transport security
ImplementedCaddy manages Let's Encrypt certificates for arctelix.com and www.arctelix.com; HTTP requests are redirected to HTTPS.
Security headers
ImplementedContent Security Policy, HSTS, frame denial, MIME-type protection, referrer and permissions policies are set on every response.
No uploads, accounts or tracking
ImplementedThe corporate site has no file upload, user accounts, analytics beacons or marketing pixels.
Contact form controls
ImplementedSame-origin and CSRF checks, server-side validation, body-size and rate limits, honeypot, no logging of message content.
Contact delivery
Configuration requiredNo delivery provider is configured. The form states explicitly that a message was not sent.
Infrastructure
German hosting is not Swiss data residency.
- Registered office
- Lucerne, Switzerland
- Production server
- Hetzner, Falkenstein, Germany
- DNS and TLS
- IONOS authoritative DNS · Caddy · Let's Encrypt
- Container
- Non-root user, read-only filesystem, health checks
- Application rate limit
- 5 requests / 15 minutes per client
- Server network boundary
- UFW permits only SSH, HTTP and HTTPS
Company practice
No broad guarantees before the evidence exists.
Client data handling
Per engagementProcessing locations, subprocessors and retention are agreed per engagement in a written data-processing agreement.
Backups and recovery
In implementationDeployment guidance exists; production targets and restore tests require a named owner.
Certifications
None claimedNo ISO, SOC or other certification is claimed. Any future audit result will be published with its scope and date.
Model training use
Under reviewNo public no-training promise is made until technical controls and provider contracts are verified.
Security reports
A responsible disclosure channel still needs a verified address.
Do not send sensitive vulnerability details through the general contact form. A dedicated security mailbox, acknowledgement target and disclosure policy will be published once approved.
- Security contact
- Pending verification
