## Site Security and Integrity
Actions speak louder than words, and transparency is the act of choosing to be vulnerable and forthright.
This page is an act of transparency: the site has been hardend where possible and is continuously monitored to ensure those protections stay active.
Monitoring Status:
Realtime Monitoring:
Realtime Monitoring:
Note: Status badges on this page are loaded through our own server proxy, so badge providers do not receive your IP address or visit data.
Audit
Platform
Grade
Verification Frequency
SSL/TLS Configuration
Quarterly
Security Headers
Quarterly
Comprehensive Scan
(Headers + TLS + SRI/CSP Checks)
Quarterly
DNSSEC
Quarterly
Cookieserve scan results as of 09/08/26: 0 cookies detected
Clicking link will take you to a 3rd party verfification service
This confirms our site does not store tracking data in visitors' browsers.
All analytics are processed server-side with no persistent identifiers retained.
Enabled: DreamShield — Daily malware scans, advanced notices regarding hosting services
Enabled: BunnyShield — WAF, DDOS mitigation, rate limiting and bot detection
Enabled: SSL Certificate Monitoring — Automated alerts before expiration, auto-renewal (provided by host)
Enabled: HTTPS Encryption — All connections force secure encryption; no unencrypted access allowed
Enabled: Clickjacking Prevention — X-Frame-Options blocks malicious embedding attempts
Enabled: Content-Type Validation — Prevents file-type confusion attacks
Enabled: Referrer Control — Sends no referrer data when clicking external links. (Other sites can’t see you came from this one.)
Enabled: Feature Restrictions — Disables intrusive browser APIs (geolocation, microphone, camera)
Enabled: HSTS Lock — Enforces HTTPS for one year minimum
Enabled: Cross-Origin-Opener-Policy — Isolates this page from other websites
Enabled: Cross-Origin-Resource-Policy — Protects this site's assets from being loaded or embedded by other websites.
Disabled: Content-Security-Policy (CSP) — Would require constant maintenance as external resources change.
Disabled: Subresource Integrity (SRI) — Scripts verified via HTTPS-only loading.
Note on Content-Security-Policy (CSP):
We omit strict CSP to maintain dynamic features (audio players, third-party tools). This limits our headers score to A rather than A+, and reduces defense-in-depth against cross-site scripting (XSS) attacks. We prioritize site functionality and maintain strong baseline security through other headers and HTTPS encryption.
Note on Subsource Integrity (SRI):
Implementing SRI would break our privacy-focused analytics. This is a deliberate tradeoff: we accept reduced runtime script verification to preserve viewer anonymity. Third-party scripts load over HTTPS to mitigate in-transit interception, acknowledging that SRI provides additional integrity checks we forego.
Quarterly: Re-run security scans, verify grades stay current, zero cookies
Continuous: SSL certificate expiry monitoring via StatusPulse, security headers and response time via Utilshed
Annually: Full infrastructure audit review
For anyone who explores this site (and actually reads the Privacy Policy), you’ll notice a common theme throughout protecting my viewers where I reasonably can. The entire site’s structure is built upon a foundation of privacy, security and safety. There are transparent disclaimers and warnings throughout the site itself, a Caring Resources page (found in the footer) for viewers who are struggling or hurting, the primary contact form is end-to-end encrypted, the backup form sends an email to an encrypted server and the backend stuff (like analytics) utilizes aggregated data so that any viewers are unable to be specifically tracked.
I have built the site this way because—though it may not be the most robust—it does feature poems that are emotionally heavy, and the trauma section specifically, may bring forward some unpleasant memories or feelings. Those viewers may feel seen or heard for possibly the first time and I wish to honor their privacy and respect any request to reach out to say, “thank you; that was me”, or anything they may share.
For this: not just the services used, but the site itself is carefully constructed to respect privacy.
This page isn't about impressing anyone. It's about proving I take your safety seriously enough to let you verify it yourself.