Security
Security, stated plainly.
What we do, what we do not claim, and how to tell us when something is wrong.
Practices
Transport and headers
Everything is served over TLS with HSTS, a strict content security policy and no third-party scripts beyond bot protection.
Least privilege
API keys are scoped per environment and per licence. Internal access follows the same rule: people and systems get the minimum they need.
Data handling
Contact submissions are stored on Cloudflare infrastructure, retained per the privacy policy and never sold. Benchmark data is aggregated and anonymised before it goes anywhere.
Vulnerability disclosure
Found something? Tell us first.
Report vulnerabilities to admin@mortgagemagic.ai with enough detail to reproduce the issue. We acknowledge reports within five working days and keep you informed while we fix what you found.
Act in good faith: do not access data that is not yours, do not degrade the service, and give us reasonable time to remediate before any public disclosure. We will not pursue good-faith research conducted within these rules.
The machine-readable policy lives at /.well-known/security.txt.