Security
What is secured here, and how.
This page names the technical measures one by one — verifiable with the tools every browser ships. What is not finished yet is at the end.
Reporting
Report a vulnerability
Anyone who finds a flaw should be able to tell us without working through a form.
Address
frank@wvs.softwareInformal, German or English. An acknowledgement usually follows within a few days. We ask for a reasonable period before a flaw is made public — and we credit reporters by name on request once it is closed.
Machine-readable
The reporting path is also published to RFC 9116 at /.well-known/security.txt — where security researchers look first.
- Scope
- this website, Tyrell Motus, Tyrell Nexus
- Languages
- German, English
- Valid until
- 1 September 2027
This website
Eight headers the browser enforces
Every one of them is readable in your browser's developer tools — network tab, any request to this site.
| Header | Value | Against what |
|---|---|---|
| Content-Security-Policy | default-src 'none' | Nothing loads that is not explicitly allowed. The default stance is denial, not permission. |
| script-src | 'self' + one hash | Scripts only from this deployment. Exactly one inline line in the head is cleared by its SHA-256 digest; change it by one character and the browser blocks it. |
| Strict-Transport-Security | max-age 1 year, includeSubDomains | No fallback to unencrypted HTTP for a year, subdomains included. |
| X-Frame-Options | DENY | This page cannot be placed in a foreign frame — no clickjacking. |
| X-Content-Type-Options | nosniff | The browser may not guess the file type. |
| Referrer-Policy | strict-origin-when-cross-origin | Foreign servers do not learn which subpage you read. |
| Permissions-Policy | camera, microphone, geolocation, payment, usb, browsing-topics = () | Six device interfaces are switched off. This page cannot request them, not even by mistake. |
| Cross-Origin-Opener-Policy | same-origin | A window we open retains no access to this one. |
Measured
This site loads nothing from foreign servers
Fonts live here
Three font families come from this deployment, none from a font service. No foreign server learns that you are reading here.
No visitor cookies
There is no counter, no measurement and no recognition. That is exactly why this site asks you nothing — a consent dialogue would have no subject.
A guard keeps it that way
Before every release a check reports any foreign resource and recomputes the digest of the one permitted script. It fails locally, before anything can fail silently in production.
No build step in between
Static HTML without a bundler: what sits in the folder goes online. There is no intermediate stage where something could slip in.
Both applications
Where the data sits, and who processes it
In full, with purpose and region.
| Component | Purpose | Region |
|---|---|---|
| Database | business data, accounts, receipts | Ireland (eu-west-1) |
| Compute nodes | image and film computation | Romania (EU-RO-1) |
| Text model | descriptions, narration scripts | self-operated, EU |
| Delivery | website and application files | Cloudflare, contract under Art. 28 GDPR |
| Backups | recovery | EU, AES-256, kept 30 days |
Individual top-tier models in Tyrell Motus require a provider outside the EU. That is stated in the application at the point where the tier is chosen — and it only happens if that tier is chosen explicitly. Locations in detail.
Candour
What is not finished here
Neither application has launched
Both run in our own house and are used daily. They are not publicly available: no pre-sale, no tariffs, no accounts. What this page states about architecture and access describes what is built — not an offer.
The official e-invoicing check is open
We name the standard and the state instead of claiming conformity.
There is no status page
Without continuous monitoring behind it, a page of green dots would be a prop. We will put one up when there is something to monitor.