SECURITY.md — adscalculator.xyz

Security baseline & audit log. SEC (security profile) MUST read this before any audit — it is the record of what's done, when, and what remains open. Update in the SAME commit as any security change. Last full audit: Aug 25, 2026.

Current Baseline (verified Aug 25, 2026)

Dependencies

HTTP Headers (_headers, Cloudflare Pages)

Build & Deploy

Client-side

Open Items

Item Trigger Notes
ads.txt AdSense activation REQUIRED before serving AdSense ads
CSP enforce After 1–2 wks clean report-only period Convert header, monitor
HSTS extension After clean period → max-age=2y + preload
Placeholder IDs in _data/site.js Before ad launch adsenseId is placeholder

Audit Log

Date Scope Result
Aug 25, 2026 Full site: deps, headers, build, client JS All above fixes applied & deployed

Rules for Next Audit

  1. Re-verify every item in Baseline (don't trust this file blindly — check live headers)
  2. New findings: fix or add to Open Items with trigger condition
  3. Append to Audit Log in the same commit as changes