Skip to main content
MutasimAI Labs

Security

What this site does, and does not, do with data.

Every statement on this page describes a control that exists in this website's source code or its DNS zone, and can be verified from outside without asking us. Where we do not have something, we say so.

What the website collects

  • One contact form, three fields: name, email, and what you are trying to change.
  • Alongside those: the time of submission, the page it came from, and which language version you used.
  • No IP address, no user agent, no country, no device fingerprint.
  • No cookies are set. No analytics, no tracking pixels, no advertising tags.
  • The page loads no resource from any other domain.

Where enquiries are stored

  • A Cloudflare D1 database hosted in Western Europe.
  • Storage is the source of truth, not email: the form only reports success once the enquiry is durably written.
  • A notification is sent to us from a dedicated sending subdomain, separate from the mailbox domain.
  • If that notification fails, the enquiry is still recorded — you are never told we have it when we do not.

Transport and browser controls

  • HSTS with a two-year max-age, includeSubDomains and preload.
  • Content-Security-Policy restricting every fetch directive to this origin.
  • frame-ancestors none, plus X-Frame-Options for older browsers.
  • X-Content-Type-Options nosniff, strict-origin-when-cross-origin referrer policy.
  • Permissions-Policy denying geolocation, microphone, camera and interest cohorts.
  • Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy set to same-origin.

Mail authentication

  • SPF, DKIM and DMARC are all published for this domain.
  • DMARC is at p=none while the domain builds sending history, with aggregate reports collected.
  • Notification mail is sent from a separate verified subdomain so the mailbox domain's SPF is never widened.

Abuse controls on the contact endpoint

  • Server-side validation that repeats every client-side rule.
  • A honeypot field that is unreachable by mouse, keyboard and screen reader.
  • Per-IP rate limiting that stores nothing and cannot be read back.
  • An origin allowlist and a request size cap.

What we do not have

We do not hold SOC 2 or ISO 27001 certification, and we are not going to imply otherwise on a security page. If your procurement process requires either, tell us early and we will give you a straight answer about where we are rather than a roadmap you cannot audit.

Accessibility

We target WCAG 2.1 Level AA. The site is tested with axe and Lighthouse on every change: contrast ratios are checked against painted pixels rather than assumed, the accent gradient is split so text never sits on a failing stop, reduced-motion preferences disable every animation, and the page remains readable with JavaScript disabled. Known gaps and fixes are tracked in the repository. If you hit a barrier, email us and we will treat it as a defect.

Reporting a vulnerability

Email hello@mautasim.com with the detail and we will acknowledge within one business day. We will not pursue anyone who reports a genuine issue in good faith.