Wira Delta Indonesia

Security Policy

How this site is run, what a report should cover, and what is in and out of scope.

In effect since Applies to wiradelta.com Systems & Software Engineering

This is an English translation of the Indonesian original. If the two differ in interpretation, the Indonesian text prevails.

The wiradelta.com site is a static site: its pages are built once with Astro and then served as they are by our own Nginx server on a rented virtual server, with Cloudflare in front of it. There are no user accounts, no login, and the server does not rebuild a page when you open it.

There are two places that accept input from visitors, and both are named here first:

  • The contact form on the Studio page. This is one small endpoint on our server that accepts a name, an email address, an organization name, and a message, sends them to us as one email, and then discards the contents. The server rejects submissions that are too large or contain characters that could inject email headers, and the number of submissions from one IP address in a short time is limited.
  • The Snapdown Pro waitlist at /snapdown/pro/. This is one small endpoint on our server that accepts an email address, stores it until its owner unsubscribes, and, through the unsubscribe link in every email, deletes it from the list on the server and from the sign-up notification emails we received.

Two Questions People Ask Most

  • Does this site store your data. Only in two places: email addresses on the waitlist, stored on our server until you unsubscribe and then deleted from the list and from our sign-up notification emails (its encrypted backup copies are gone at most 7 days later), and contact form messages, which our server forwards to our email inbox without storing them on the server. The details are in the Privacy Policy.
  • Does this site run third-party code. When a page opens, no third-party scripts, fonts, or libraries are loaded; everything is served from wiradelta.com. The only values stored in your browser are your theme choice and your scroll position when switching language. If Google Analytics is installed later, this page and the Privacy Policy are updated first.

What Is in Place on the Server

  • HTTPS is required. HTTP requests are redirected to HTTPS, and HSTS is set with a short lifetime that is raised once the site is stable.
  • Basic security headers are set in Nginx. Anyone can check the exact list by reading the server's response headers.
  • The site's source code is not published: only the build output is served.

This list states what is in place, not a guarantee that there are no flaws. That is why the reporting channel below exists.

Reporting a Vulnerability

This site's repository is private, so GitHub Security Advisories cannot be reached by outside reporters. Send reports to security@wiradelta.com.

Include the address of the affected page or endpoint, the steps to reproduce it, and the impact you expect. Please do not publish a finding before we have had a chance to fix it.

There is no bug bounty program and no guaranteed response time. We are a small studio, and honesty about that is more useful than a promise we cannot keep.

Vulnerabilities in our applications are reported through each product's own channel: Wira Desk and WorshipDeck through GitHub Security Advisories on their repositories, Snapdown through the address named in the Snapdown security policy.

Scope

In scope:

  • injection of content or scripts into pages served by wiradelta.com;
  • flaws in the waitlist endpoint and its unsubscribe link: reading, changing, or deleting other people's addresses, injecting data that the server executes, or using the endpoint to send email to third parties;
  • leaks of the private repository's contents through the published build output, for example source maps or configuration files that end up being served;
  • misconfiguration of Nginx, TLS, DNS, or hosting that opens redirects to other sites, origin spoofing, or subdomain takeover;
  • incorrect security headers that cause an impact that can be demonstrated.

Out of scope, with the reason:

  • flaws in third-party services (Cloudflare, GitHub, Tencent Cloud, our email delivery service), because we do not control them; report them directly to the provider;
  • availability attacks (denial of service), because this public site comes with no SLA (see Terms and Conditions §6);
  • attacks that require access to a visitor's device that an attacker already controls, because at that point the attacker does not need a flaw in our site;
  • errors in written content, such as typos or claims you believe are wrong; send those to hello@wiradelta.com, because they are not vulnerabilities.

Changes

If the site adds an endpoint, form, or other service that accepts data, this page is updated before that feature goes live. The date at the top shows the version currently in effect.

Language

This is an English translation of the Indonesian original. If the two differ in interpretation, the Indonesian text prevails.