Security & Trust

This page details how PositiveBacklink protects user data and how to report vulnerabilities. We treat security as an ongoing commitment, not a checkbox.

Data protection

Security headers

Every response includes the following headers (verifiable via securityheaders.com):

HeaderValue
Strict-Transport-Securitymax-age=63072000; includeSubDomains; preload
X-Frame-OptionsSAMEORIGIN
X-Content-Type-Optionsnosniff
Referrer-Policystrict-origin-when-cross-origin
Content-Security-PolicyStrict allow-list, no unsafe-eval
Permissions-Policycamera/mic/geo disabled

Authentication

Infrastructure

Vulnerability disclosure

If you discover a security vulnerability, please email security@positivebacklink.com with:

We commit to:

Safe harbor: Good-faith research that follows this policy is welcomed and will not result in legal action. Please do not access, modify, or exfiltrate user data.

Compliance roadmap