mortgagemagic.ai
Menu

Security

Security, stated plainly.

What we do, what we do not claim, and how to tell us when something is wrong.

Practices

Transport and headers

Everything is served over TLS with HSTS, a strict content security policy and no third-party scripts beyond bot protection.

Least privilege

API keys are scoped per environment and per licence. Internal access follows the same rule: people and systems get the minimum they need.

Data handling

Contact submissions are stored on Cloudflare infrastructure, retained per the privacy policy and never sold. Benchmark data is aggregated and anonymised before it goes anywhere.

Vulnerability disclosure

Found something? Tell us first.

Report vulnerabilities to admin@mortgagemagic.ai with enough detail to reproduce the issue. We acknowledge reports within five working days and keep you informed while we fix what you found.

Act in good faith: do not access data that is not yours, do not degrade the service, and give us reasonable time to remediate before any public disclosure. We will not pursue good-faith research conducted within these rules.

The machine-readable policy lives at /.well-known/security.txt.