Website Security Policy
Security summary:
The static architecture reduces attack surface by avoiding a heavy CMS and using local CSS/JavaScript. Production security still depends on hosting, TLS, headers, forms and third-party integrations.
Data minimization
Do not collect prescription images, payment details or sensitive medical information through generic forms unless a specifically designed compliant system is implemented.
Production controls
Use HTTPS, secure headers, least-privilege hosting access, regular dependency review, backups and monitoring. Keep administrative credentials out of public files.
Vulnerability reporting
Publish a real security contact before launch and consider adding a security.txt file once the responsible mailbox is configured.