Security overview

Website

This website is static: no login, no database, no third-party scripts. Security headers (CSP, HSTS, nosniff, Referrer-Policy, COOP/CORP) are set at server level. Hosting and deployment controls are fixed in ADR-003.

Delivery

In projects we work with least privilege, secrets management, secure SDLC practices (SBOM, dependency scanning), redacted logging and defined incident processes.

Reports

Security reports about this website: support@spnorth.at (placeholder). SPNORTH does not guarantee certification or compliance; certifications are only stated with verifiable status.

Reviewed on 2026-09-16 · Owner: sec-lead · Review: legal-review