Website policy
Website security
This page summarizes the security posture of the landing-page package without claiming a certification or compliance status.
Last updated: 19 August 2026Public website controls
The Next.js application applies a restrictive content security policy, secure response headers, request-size limits, same-origin form checks and rate limiting.
Demo-request protection
Accepted requests are validated, protected by a honeypot and stored using AES-256-GCM when the required storage key is configured. Raw form content is not written to application logs.
Product boundaries
The website does not expose provider credentials, device credentials, Qanivo internals, visitor data or administrative controls.
Responsible reporting
Potential security issues can be reported to hello@niosk.net with enough detail to reproduce the concern. Do not include sensitive third-party data.