As a cybersecurity provider, EBH Security applies to its own platform the standards it recommends to its clients. This page describes the measures in place and the responsible disclosure procedure for a vulnerability.
TLS 1.3 across all exchanges, HSTS enabled with preloading.
A CSP restricts which script, style, and resource origins are allowed to execute on this site.
X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy are applied across all pages.
Forms are protected against automated submissions without relying on a third-party tracking service.
Technical log retention is limited to what is necessary for the site's security and proper operation, in line with the privacy policy.
Any vulnerability identified on this site can be responsibly reported via the security.txt file available at the domain root, or in writing to [email protected]. EBH Security commits to acknowledging any legitimate report.