If you sell security, you publish your threat model.
Anyone can claim to ship secure software. The proof is whether you've thought through your own surface area, written it down, and offered an honest place to send a report. That's what this page is.
The site you're reading is a static Astro build deployed on Vercel. It has no user accounts, no payment flow, no CMS. The attack surface is small — but small is not zero, and "static" is not a synonym for "safe." The same supply-chain, header, and form-pivot risks that hit any production app apply here.
What follows is the threat model: what's worth attacking, who would attack it, and what's in place to make that hard. Read with skepticism. If something looks wrong, the disclosure flow is at the bottom.