Security
How we approach security
A high-level, factual overview of public-site controls and the current reporting path. This page does not claim a certification or absolute security.
Last updated: 31 July 2026
Public website controls
- HTTPS is enforced by the application path, with HSTS configured for production responses.
- A Content Security Policy limits scripts, connections, framing, and other browser capabilities.
- Browser headers prevent framing, MIME-type sniffing, and access to camera, microphone, and geolocation.
- Nonessential analytics is disabled unless configured and a visitor accepts it.
Product access
Private product areas use authenticated, role-based application access. The product architecture separates public website content from application and service APIs. Customer documents are not published through this website.
No website can promise perfect protection. Security controls, dependencies, and operating processes require ongoing review throughout the private beta.
Report a security issue
Email contact@estospaces.com with the subject “Security report”. Include the affected URL, what you observed, and safe reproduction steps. Do not include real customer data or publicly disclose an unresolved issue.
The verified domain mailbox above is the public security-reporting path. We do not publish a response-time promise. A machine-readable security.txt points to the same address.