Legal center · Security

Public-site security and protected-download controls.

Public pages are joined by a server-side Worker boundary for account sessions and protected downloads. The company site does not expose a general public API.

Current state

Static content with a server-backed boundary

Most public content is served as static HTML and CSS . Account and session requests, plus protected package downloads, cross a server-side Worker boundary.

Approved package downloads and their verification files are public without sign-in. Account services and paid capabilities retain their own access checks. The company site exposes no general public API.

Current boundaries

Controls in production

Verified public downloads

Package routes apply request limits and validate the approved release and stored file identity before delivery.

Fail-closed delivery

If release selection, file integrity, or required trust material cannot be verified, package delivery stops.

Public trust material

Checksums, signatures, and public keys remain available so files received elsewhere can be verified independently.

Route-level protection

Sensitive Worker responses use no-store caching, restrictive security headers, and request-method limits.

Abuse controls

Account and authentication routes apply route-level rate limits when the deployment control is available.

Secret handling

Runtime credentials stay in deployment settings and are not published with static site assets.

Disclosure

Report security issues privately.

Do not file public issues for security findings. Use the organization security policy for affected repositories, or email security@altifigence.com.

Public issues are appropriate for documentation bugs, broken links, accessibility problems, and ordinary website defects.

Read the public security policy.