RTRadu Todea ∴ / Under the hood ← Back to the story

∴Under the hood

This site practises what I preach.

Everything on this page is measured live, in your browser, while you read — not written once and hoped for. The short version, if you’re not technical: no tracking, nothing worth stealing, and hard to tamper with.

Security headers
—
Requests to other companies
—
Cookies set on your device
—
Email addresses in the source
—

01Security headers

Checked live, right now.

Your browser just asked this server for its own response headers. Here is what came back — and what each one protects you from.

    02Privacy

    Counted, not promised.

    No analytics, no ad pixels, no fonts or scripts borrowed from other companies. Don’t take my word for it — these numbers come from your own browser.

      03Your fingerprint

      What any website can see.

      Before you click anything, every page you open can read this much about your device — no permission asked. It’s shown here so you can see it for yourself. This page doesn’t store or send any of it: the counter above would give it away.

      Put together, that’s a fingerprint

      —

      Combined, details like these can recognise a device across sites without a single cookie. Change almost anything — browser, window size, language — and it changes. Close this tab and it’s gone.

      04Threat model

      If I were attacking this site.

      Every system gets a threat model — this one included. What’s at stake, how someone would go after it, and what stands in the way.

      What’s at stakeThe threatWhat stops it
      My contact details Scrapers harvesting email addresses Encrypted at build time with a fresh key, split into shards among decoys, decrypted only after a trusted human gesture — and wiped after 60 seconds.
      Your privacy Tracking and profiling No cookies, no analytics, zero third-party requests, and a strict referrer policy. There is nothing to opt out of.
      This page Script injection (XSS) A strict Content-Security-Policy: only this site’s own scripts run — no inline code, no eval. Trusted Types go further: not even this site’s own code may turn a string into HTML, so there’s no sink left to inject into.
      Your clicks Clickjacking The site refuses to be framed by anyone — frame-ancestors 'none' and X-Frame-Options: DENY.
      The code A poisoned dependency A handful of runtime libraries, pinned by a lockfile and bundled at build time. Nothing is fetched from a CDN while you browse.
      The connection Downgrade and interception HTTPS only, with HSTS for two years and ready for the browsers’ preload list.
      The honest part A determined human Anything a browser can show, a person can read. The goal isn’t secrecy — it’s raising the cost and shrinking the exposure. The same thing I do for the systems I test.

      05Try to break it

      Go on, try to break it.

      Paste your favourite XSS payload. The page will genuinely try to turn it into HTML — and your own browser will tell you what stops it. Nothing you type leaves this page.

      or ⌘ / Ctrl + Enter

        06Accessibility

        Built for everyone.

        A security engineer’s site should work for every visitor, not just the ones with a mouse and perfect eyesight. Checked live, against the rules the web agrees on (WCAG 2.2) — including your own settings.

          07Performance

          Light on its feet.

          A 3D particle world doesn’t have to be heavy. No framework, no page builder — hand-written HTML, CSS and JavaScript, and the 3D engine only loads when it’s needed.

            08Build

            Where this copy came from.

            Built
            —
            Commit
            —
            Runtime libraries
            —
            Made with
            Vite · Three.js · GSAP · Lenis — and a lot of hand-written code

            09Responsible disclosure

            Found something?

            Brilliant — tell me. I read every responsibly disclosed report myself, and a real finding earns your name a place below. Please keep your testing to this site, and give me a fair chance to fix it before you talk about it.

            Hall of fame

            1. Nobody yet.Be the first