Filing Room

Security

How this is built, and how to report something

In one line: the safest way to hold reader data is not to have any, and that is the design.

This page describes how the site is built and how to report something. It is written plainly rather than as a compliance statement, because a compliance statement nobody can check is worth nothing.

There is almost nothing to breach

No accounts, no passwords, no sessions, no payment details, no email list, no comments, no uploads. The site holds no reader data, so there is no reader data to lose. The privacy page has the detail.

The pages

Every page is static HTML and CSS built ahead of time. There is no server-side code, no database, and no request-time rendering, so the usual categories of web vulnerability have nowhere to happen: there is no query to inject into, no session to hijack, and no upload to abuse.

There is no JavaScript on this site at all, and that is enforced rather than remembered. The content security policy served with every page declares no script source under a default of none, so a browser will refuse to run a script here even if one somehow reached a page. The policy also blocks framing, restricts images to this site and our own card host, and forbids form submission.

Fonts are served from this domain. Nothing on a page is loaded from a third party.

The code

The core of the pipeline has no runtime dependencies. Rendering card images uses two libraries, and reading PDFs uses one, all of them at build time only: none of that code ever runs in your browser, because none of it is shipped to your browser.

The repository is private. Transparency here is about method rather than source: the document, the page number, the file hash and the arithmetic are all published beside every figure, which is what lets you check a claim. A public repository would mainly hand out a working clone and a tuned crawler.

How documents are retrieved

We read public filings from the regulator's and the exchanges' own public pages. No login, no credential, no paywall and nothing that is not already public.

The retrieval is deliberately polite: a minimum interval between requests to the same host, backing off when a host is busy, and no request repeated for a document already held. It is meant to look like a careful reader rather than a crawler, because these are public documents on a regulator's site paid for by the public.

Every document is stored under a hash of its own contents, so the copy a figure was read from can always be identified, and a document that changed is a different document rather than a silent overwrite.

Published images

Card images are named with a hash of everything drawn on them and are never overwritten. Correct a figure and the corrected card appears at a new address while the old one stays where it is, because by then it may be in a hundred chat threads and changing it silently would be the wrong kind of quiet.

Reporting something

Security issues: [email protected]. Machine-readable details are at /.well-known/security.txt.

Please include enough detail to reproduce it. We will acknowledge, fix what needs fixing, and tell you what happened. There is no bug bounty and no money involved, which is stated plainly rather than implied.

Please do not run automated scanning against the site. It is four static pages and you will learn more by reading the source, which is served to you in full.

Wrong figures are the more useful report. If a number here does not match the document we cite, that is a defect in the thing this site exists to do. Send it to the same address. It will be checked and, if wrong, corrected in public with the correction dated.