Trust Center
We Practice What We Advise
As a cybersecurity firm, we hold ourselves to the same standards we recommend to our clients. This page documents — verifiably — how this website and our communications are secured.
Everything on this page can be independently verified with public tools (securityheaders.com, SSL Labs, DNSViz, MXToolbox).
Transport Security
- TLS 1.3 with automatic HTTPS redirection
- HSTS enabled (6 months, includeSubDomains)
- DNSSEC active on brainfortsecurity.com
Application Hardening
- Content-Security-Policy restricting all external code
- X-Frame-Options: DENY and frame-ancestors 'none'
- nosniff, strict Referrer-Policy, minimal Permissions-Policy
Email Authenticity
- SPF restricted to Google Workspace senders
- DKIM signatures on all outgoing mail
- DMARC monitoring in place
Availability
- Served from Cloudflare's global edge network
- Fully static architecture — no database or origin server to breach
- Version-controlled deployments with CI checks
Data & Privacy
- Minimal data collection by design — no tracking cookies
- PIPEDA and Quebec Law 25 aligned privacy practices
- Corporate data in Google Workspace with enforced MFA
Vulnerability Disclosure
- Published responsible disclosure policy with safe harbor
- Signed security.txt at /.well-known/security.txt
- PGP key available for encrypted reports
Security Contact
Found something? Tell us — encrypted if possible.