Prototypes Prototype docsP11 · Docs and assistant
Security and data
DocsPage 13 of 30

Security and data

What the prototypes' server sends, stores and deletes.

Headers

The server sends a content security policy with every response that allows scripts, styles, images and connections from the site itself only, frames from the site and from blob addresses, and no plugins. It also sends HSTS, nosniff, a referrer policy of no-referrer, and noindex.

The login

The deployed site is closed behind basic auth until SITE_GATE is set to off. Without a user name and a password set as secrets, it answers 401 to everyone. The comparison runs in constant time.

What is stored

P6 stores public keys, ciphertext and wrapped keys. P7 stores case numbers, wrapped keys and ciphertext. P8 stores field changes. P9 stores bookings with a name and an email address, and the emails it wrote. P11 stores each question. The server deletes all of it after 7 days.

What is never stored

Private keys, receipt codes, passwords and plain text of the encrypted prototypes.

Previous: Docs and assistant (P11). Next: How the prototypes are checked.

How Prototype docs is built

The pages are written in Markdown and built into these pages and an index of 154 sections. The assistant answers from the index, and every answer names the sections it was taken from.