Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Security Policy

As a cybersecurity provider, EBH Security applies to its own platform the standards it recommends to its clients. This page describes the measures in place and the responsible disclosure procedure for a vulnerability.

Transport encryption

TLS 1.3 across all exchanges, HSTS enabled with preloading.

Content Security Policy

A CSP restricts which script, style, and resource origins are allowed to execute on this site.

Security headers

X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy are applied across all pages.

Anti-bot protection

Forms are protected against automated submissions without relying on a third-party tracking service.

Logging

Technical log retention is limited to what is necessary for the site's security and proper operation, in line with the privacy policy.

Responsible disclosure

Any vulnerability identified on this site can be responsibly reported via the security.txt file available at the domain root, or in writing to [email protected]. EBH Security commits to acknowledging any legitimate report.