Security
Security at Korevor
Last updated: 2026-10-06
Our approach
Security is part of every build from the first day, not something added at the end. Every system we build is different, so its protections are chosen for the job it does and the information it handles. A few things are true of all of them.
On every build
- Encrypted connections. Anything we put on the internet is served over HTTPS only.
- No secrets in the code. Passwords and API keys are kept in an encrypted vault, and every change is checked for leaked secrets before it is committed.
- Private server access. Where we run a server, it is managed over a private, encrypted network, and its admin ports are closed to the public internet.
This website
korevor.com is served through Cloudflare's global network over HTTPS only (TLS 1.2 or newer), with HSTS set for one year, covering subdomains and ready for preload. Every page is sent with a strict Content-Security-Policy, X-Frame-Options DENY, nosniff, and a Permissions-Policy that switches off camera, microphone, location and payment access. It runs PostHog product analytics with autocapture, session recording and heatmaps turned off. It records page views (including time on page and how far the page was scrolled) and a small set of named events, such as a completed booking. PostHog stores an anonymous visitor identifier in localStorage and a cookie. There are no advertising trackers.
Responsible disclosure
Found a vulnerability in a Korevor property? Email security@korevor.com. We acknowledge reports within 2 business days, and we do not pursue legal action against good-faith research that avoids privacy violations and service disruption. The same contact is published in machine-readable form at /.well-known/security.txt (RFC 9116).