Legal center · Security
Public-site security and protected-download controls.
Public pages are joined by a server-side Worker boundary for account sessions and protected downloads. The company site does not expose a general public API.
Current state
Static content with a server-backed boundary
Most public content is served as static HTML and CSS . Account and session requests, plus protected package downloads, cross a server-side Worker boundary.
Approved package downloads and their verification files are public without sign-in. Account services and paid capabilities retain their own access checks. The company site exposes no general public API.
Current boundaries
Controls in production
Verified public downloads
Package routes apply request limits and validate the approved release and stored file identity before delivery.
Fail-closed delivery
If release selection, file integrity, or required trust material cannot be verified, package delivery stops.
Public trust material
Checksums, signatures, and public keys remain available so files received elsewhere can be verified independently.
Route-level protection
Sensitive Worker responses use no-store caching, restrictive security headers, and request-method limits.
Abuse controls
Account and authentication routes apply route-level rate limits when the deployment control is available.
Secret handling
Runtime credentials stay in deployment settings and are not published with static site assets.
Disclosure
Report security issues privately.
Do not file public issues for security findings. Use the organization security policy for affected repositories, or email security@altifigence.com.
Public issues are appropriate for documentation bugs, broken links, accessibility problems, and ordinary website defects.