HTTPS and transport policy
The public site redirects HTTP and www requests to the canonical HTTPS origin. The edge adds HSTS and a restrictive referrer policy.
This page separates controls visible in the public website implementation from product-security evidence that must be supplied and reviewed during procurement. It does not claim a certification or independent assurance report.
These statements are bounded to the marketing website and its form worker. They are not evidence about an unaudited product environment.
The public site redirects HTTP and www requests to the canonical HTTPS origin. The edge adds HSTS and a restrictive referrer policy.
The deployed worker defines a Content Security Policy, frame restrictions, MIME-sniffing protection, and a permissions policy for the public website.
Public forms use same-origin checks, a honeypot, a short time trap, input-length limits, validation, and duplicate-submission controls before forwarding a lead.
Analytics is loaded only after an affirmative analytics-consent choice. Visitors can reopen cookie settings from the footer.
Do not infer product controls from marketing copy. Security, privacy, legal, and procurement owners should review dated evidence and ensure the executed agreement matches the proposed configuration.
Send your scope, systems, data categories, jurisdictions, and required evidence. Do not send credentials, production data, or confidential records through the public contact form.
Email security@getgangly.com