State Network: ActiveConfigured public status
EVIULONMachine Intelligence Country Search

PUBLIC SECURITY

Security and responsible disclosure

The portal minimizes attack surface through static delivery, first-party assets, strict headers and explicit boundaries around sensitive information.

Entity ID
EVI-WEB-SECURITY-001
Status
Static package hardened · host enforcement requires deployment verification
Authority
National Engineering Directorate
Data period
Current registry
Last reviewed

Architecture

Core pages are static HTML with no database or server runtime requirement. Optional JavaScript is small, first-party and enhancement-only. The package includes Apache and edge-host header configurations.

Security headers

The production policy includes HTTPS redirection, HSTS, a restrictive Content Security Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and frame restrictions. The actual deployed response headers must be verified on the chosen host.

Public data classification

PUBLIC
Approved for unrestricted public distribution.
PUBLIC-AGGREGATED
Approved aggregate that does not expose sensitive underlying records.
CIVIC
Available to an authorized civic context, not the open web.
RESTRICTED
Limited by identity, purpose or security need.
STATE-INTERNAL
Operational information excluded from public release.

Credential safety

No passwords, tokens, private keys, cookies or raw credential values are stored in the repository, generated memory or public documentation. The credential inventory records only safe filenames, intended use and unresolved custody boundaries.

Transactional services

No live public form is enabled. A future endpoint requires server-side validation, CSRF protection, rate limiting, contextual output encoding, abuse controls, secure retention and non-debug error responses.

Responsible disclosure

No authorized disclosure mailbox was present in the repository. A live security contact must be established before production. The package provides a placeholder security.txt that clearly states the unresolved channel instead of inventing one.

Deployment limitations

Static files cannot themselves enforce TLS versions, HTTP/3, HSTS or edge caching. Those controls depend on the production host and remain deployment acceptance checks.

Authority and record status

Responsible authority: National Engineering Directorate.

This page describes packaged controls and explicitly separates them from host-level enforcement that has not occurred.

Revision date: . Public corrections may be initiated through the diplomatic contact route.

Continue exploring