Security & Trust

Trust statements carry a status.

This register separates controls that are implemented on this website from practices that still require technical or contractual confirmation. Nothing here is a certification claim.

Corporate website

A minimal public data surface.

  • Transport security

    Implemented

    Caddy manages Let's Encrypt certificates for arctelix.com and www.arctelix.com; HTTP requests are redirected to HTTPS.

  • Security headers

    Implemented

    Content Security Policy, HSTS, frame denial, MIME-type protection, referrer and permissions policies are set on every response.

  • No uploads, accounts or tracking

    Implemented

    The corporate site has no file upload, user accounts, analytics beacons or marketing pixels.

  • Contact form controls

    Implemented

    Same-origin and CSRF checks, server-side validation, body-size and rate limits, honeypot, no logging of message content.

  • Contact delivery

    Configuration required

    No delivery provider is configured. The form states explicitly that a message was not sent.

Infrastructure

German hosting is not Swiss data residency.

Registered office
Lucerne, Switzerland
Production server
Hetzner, Falkenstein, Germany
DNS and TLS
IONOS authoritative DNS · Caddy · Let's Encrypt
Container
Non-root user, read-only filesystem, health checks
Application rate limit
5 requests / 15 minutes per client
Server network boundary
UFW permits only SSH, HTTP and HTTPS

Company practice

No broad guarantees before the evidence exists.

  • Client data handling

    Per engagement

    Processing locations, subprocessors and retention are agreed per engagement in a written data-processing agreement.

  • Backups and recovery

    In implementation

    Deployment guidance exists; production targets and restore tests require a named owner.

  • Certifications

    None claimed

    No ISO, SOC or other certification is claimed. Any future audit result will be published with its scope and date.

  • Model training use

    Under review

    No public no-training promise is made until technical controls and provider contracts are verified.

Security reports

A responsible disclosure channel still needs a verified address.

Do not send sensitive vulnerability details through the general contact form. A dedicated security mailbox, acknowledgement target and disclosure policy will be published once approved.

Security contact
Pending verification