Skip to content
Wagner Virtual Studios

Security

What is secured here, and how.

This page names the technical measures one by one — verifiable with the tools every browser ships. What is not finished yet is at the end.

Reporting

Report a vulnerability

Anyone who finds a flaw should be able to tell us without working through a form.

Address

frank@wvs.software

Informal, German or English. An acknowledgement usually follows within a few days. We ask for a reasonable period before a flaw is made public — and we credit reporters by name on request once it is closed.

Machine-readable

The reporting path is also published to RFC 9116 at /.well-known/security.txt — where security researchers look first.

Scope
this website, Tyrell Motus, Tyrell Nexus
Languages
German, English
Valid until
1 September 2027

This website

Eight headers the browser enforces

Every one of them is readable in your browser's developer tools — network tab, any request to this site.

HeaderValueAgainst what
Content-Security-Policydefault-src 'none'Nothing loads that is not explicitly allowed. The default stance is denial, not permission.
script-src'self' + one hashScripts only from this deployment. Exactly one inline line in the head is cleared by its SHA-256 digest; change it by one character and the browser blocks it.
Strict-Transport-Securitymax-age 1 year, includeSubDomainsNo fallback to unencrypted HTTP for a year, subdomains included.
X-Frame-OptionsDENYThis page cannot be placed in a foreign frame — no clickjacking.
X-Content-Type-OptionsnosniffThe browser may not guess the file type.
Referrer-Policystrict-origin-when-cross-originForeign servers do not learn which subpage you read.
Permissions-Policycamera, microphone, geolocation, payment, usb, browsing-topics = ()Six device interfaces are switched off. This page cannot request them, not even by mistake.
Cross-Origin-Opener-Policysame-originA window we open retains no access to this one.

Measured

This site loads nothing from foreign servers

Fonts live here

Three font families come from this deployment, none from a font service. No foreign server learns that you are reading here.

No visitor cookies

There is no counter, no measurement and no recognition. That is exactly why this site asks you nothing — a consent dialogue would have no subject.

A guard keeps it that way

Before every release a check reports any foreign resource and recomputes the digest of the one permitted script. It fails locally, before anything can fail silently in production.

No build step in between

Static HTML without a bundler: what sits in the folder goes online. There is no intermediate stage where something could slip in.

Both applications

Where the data sits, and who processes it

In full, with purpose and region.

ComponentPurposeRegion
Databasebusiness data, accounts, receiptsIreland (eu-west-1)
Compute nodesimage and film computationRomania (EU-RO-1)
Text modeldescriptions, narration scriptsself-operated, EU
Deliverywebsite and application filesCloudflare, contract under Art. 28 GDPR
BackupsrecoveryEU, AES-256, kept 30 days

Individual top-tier models in Tyrell Motus require a provider outside the EU. That is stated in the application at the point where the tier is chosen — and it only happens if that tier is chosen explicitly. Locations in detail.

Candour

What is not finished here

Neither application has launched

Both run in our own house and are used daily. They are not publicly available: no pre-sale, no tariffs, no accounts. What this page states about architecture and access describes what is built — not an offer.

The official e-invoicing check is open

We name the standard and the state instead of claiming conformity.

There is no status page

Without continuous monitoring behind it, a page of green dots would be a prop. We will put one up when there is something to monitor.