Security & launch / Observed August 27, 2026

Evidence, not badges.

A scoped account of what is verified, what is configured, and what remains open across the public marketing surface and the separate HireNest application.

Observed baseline

Six lines in the release ledger.

“Configured” means the control exists in this source. “Verified” means a stated behavior was checked. Neither word is a certification or a promise that no vulnerability exists.

01
Verified

Static marketing surface

The marketing files contain no account flow, password field, checkout, upload, or site-handled enquiry form. Contact opens email. They load no third-party analytics, advertising, session-replay, CAPTCHA, or bot-protection script; routine hosting logs may still be processed.

02
Verified

Public / private boundary

Account access occurs on the separate app host. Unauthenticated checks against representative workspace, campaign, search-operations, and mail-bootstrap API routes returned 401; reviewed application code requires the current user and applies user-ID ownership filters.

03
Verified live

Marketing browser policy

The live marketing response was checked for CSP, HSTS, MIME, frame, referrer, permissions, opener, and DNS-prefetch protections on August 27, 2026. The supplied release template tightens that baseline; every deployment still gets a response-header regression check.

04
Headers verified live

App headers / session limit

The app host now sends CSP, HSTS, MIME, frame, referrer, permissions, opener, and DNS-prefetch protections. Its stateless JWT access remains configured around seven days, with no verified server-side logout revocation. The checked 401 boundary is not evidence of PostgreSQL row-level security.

05
Verified live

TLS and canonical handoff

The HTTPS certificate, HTTP-to-HTTPS redirect, and legacy apex-to-app handoff were checked live on August 27, 2026. The release config also makes the canonical host and clean-path intent explicit. None of this establishes or claims Cloudflare origin lock; proxy state and origin access rules remain separate deployment facts.

06
Owner action

Search and measurement

Canonical URLs, crawl rules, a sitemap, and social metadata are present. Search Console ownership and sitemap submission require account access. No analytics script is installed; adding one requires a privacy, CSP, and consent review—not a ranking guarantee.

Not claimed

No certification, independent penetration test, guaranteed uptime, guaranteed security, guaranteed search ranking, PostgreSQL RLS, Firebase, Supabase, Clerk, or Cloudflare origin lock is represented by this marketing site.

Release sequence

Review → test → deploy → inspect the edge → record what remains.

Security-sensitive application work is not folded into a marketing launch claim. It stays visible as a separate deployment gate until implemented and rechecked.

Report an issue

If you believe you found a security issue affecting a HireNest-controlled surface, email Ash@ashwebsaas.com with the affected URL, steps to reproduce, and impact. Please do not include passwords, access tokens, or unrelated personal data. No public bug bounty or response-time guarantee is offered.