Security Headers
Public HTTPS responses are configured to send HSTS, clickjacking protection, MIME-sniffing protection, a strict referrer policy, and a locked-down browser permissions policy.
Strict-Transport-Security
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy blocks camera, microphone, geolocation, payment, and USB access.
CSP Status
Content Security Policy is not enforced yet. Nogosee uses WordPress, theme, plugin, analytics, sharing, and inline script surfaces that need a compatibility inventory before a CSP can be safely enabled.
The intended path is inventory first, report-only testing second, enforcement last.
Secrets Boundary
Public pages must not expose Cloudflare, WordPress admin, Google service-account, Worker admin, or pipeline credentials. Public API and CSV/RSS endpoints stay capped; admin and monitor endpoints require separate secrets.
Data Boundary
Public exports are samples for evaluation and normal research. Full source baskets, matching logic, scoring weights, prompts, provider routing, anti-abuse controls, and complete archives are not published.
Operational Monitoring
Nogosee monitors article production, public-signal freshness, regional database health, product-event measurement, newsletter readiness, and plugin update health through Worker status endpoints.
Responsible Scope
Nogosee does not invite vulnerability testing against the live site without prior permission. Send correction, security, or access-boundary concerns through the contact path.