∴Under the hood
This site practises what I preach.
Everything on this page is measured live, in your browser, while you read — not written once and hoped for. The short version, if you’re not technical: no tracking, nothing worth stealing, and hard to tamper with.
You’re on a development server. Security headers are added by the host in production, so some checks below show what a visitor would see there.
- Security headers
- —
- Requests to other companies
- —
- Cookies set on your device
- —
- Email addresses in the source
- —
01Security headers
Checked live, right now.
Your browser just asked this server for its own response headers. Here is what came back — and what each one protects you from.
02Privacy
Counted, not promised.
No analytics, no ad pixels, no fonts or scripts borrowed from other companies. Don’t take my word for it — these numbers come from your own browser.
03Your fingerprint
What any website can see.
Before you click anything, every page you open can read this much about your device — no permission asked. It’s shown here so you can see it for yourself. This page doesn’t store or send any of it: the counter above would give it away.
Put together, that’s a fingerprint
—
Combined, details like these can recognise a device across sites without a single cookie. Change almost anything — browser, window size, language — and it changes. Close this tab and it’s gone.
04Threat model
If I were attacking this site.
Every system gets a threat model — this one included. What’s at stake, how someone would go after it, and what stands in the way.
frame-ancestors 'none' and X-Frame-Options: DENY.
05Try to break it
Go on, try to break it.
Paste your favourite XSS payload. The page will genuinely try to turn it into HTML — and your own browser will tell you what stops it. Nothing you type leaves this page.
06Accessibility
Built for everyone.
A security engineer’s site should work for every visitor, not just the ones with a mouse and perfect eyesight. Checked live, against the rules the web agrees on (WCAG 2.2) — including your own settings.
07Performance
Light on its feet.
A 3D particle world doesn’t have to be heavy. No framework, no page builder — hand-written HTML, CSS and JavaScript, and the 3D engine only loads when it’s needed.
08Build
Where this copy came from.
- Built
- —
- Commit
- —
- Runtime libraries
- —
- Made with
- Vite · Three.js · GSAP · Lenis — and a lot of hand-written code
09Responsible disclosure
Found something?
Brilliant — tell me. I read every responsibly disclosed report myself, and a real finding earns your name a place below. Please keep your testing to this site, and give me a fair chance to fix it before you talk about it.
Hall of fame
- Nobody yet.Be the first