¿Prefieres español? Ver esta página en español
Trust

Security posture

What this static site and Fornax Strength actually do today — no Express app, no VPS claims, no live form API.

This website

  • Hosted as static files on Cloudflare Pages
  • HTTPS provided by Cloudflare
  • Response headers in _headers: X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy
  • No contact or newsletter API — those routes are not hosted here

What this host does not do

  • No Express server, rate-limited APIs, or honeypot backend
  • No VPS process isolation on this site
  • No HSTS set by an application server
  • No backups of form submissions — forms are not live

Fornax Strength

  • Local-first workout storage on the device
  • No third-party ad SDKs
  • Published APK checksums for integrity checks
  • Educational / non-medical framing

Client code

  • No secrets in the static JavaScript
  • Language preference may be stored locally in the browser
  • APK bytes and checksum file are published as-is
  • This is not a Flutter web app

Responsible disclosure

Found a vulnerability? Email telosfornax@gmail.com with topic security. There is no working contact API. Please avoid public disclosure until we have had a reasonable window to fix. Do not access other people’s data or disrupt production.