In short
- Website security and product security are different. Both are described here.
- We describe the controls in place. We make no claim of absolute security, certification or independent penetration testing.
- Report vulnerabilities privately to security@chamerondigital.com.
This summary helps you find your way. The full text below is what applies.
Website security and product security
This policy covers two different things: the security of this website and its enquiry service, which we operate, and the security features of our software, which runs on computers your business controls. Your own security practices matter most for the second.
This website and enquiry service
- Encryption in transit: the website is served over HTTPS through Cloudflare, and browsers are told to use HTTPS only (HTTP Strict Transport Security).
- Security headers: a strict Content Security Policy that allows scripts, styles and fonts only from this domain; X-Content-Type-Options; X-Frame-Options to prevent framing; Referrer-Policy; Permissions-Policy turning off camera, microphone, location and other features; and cross-origin isolation headers.
- Only the built website is published: source code, configuration and repository files are not served. The build fails if a file that is not part of the website, or something that looks like a secret, would be published.
- Enquiry service: requests are accepted only from this website, as JSON, with a size limit. Every field is validated on the server. Requests are rate-limited per connection, a hidden field catches simple bots, and, once switched on, Cloudflare Turnstile checks for automated abuse. Enquiries go to a fixed inbox and are not stored in a database. Personal details are not written to logs or sent to analytics.
- Secrets: keys for email delivery and bot protection are kept as encrypted secrets in Cloudflare, never in website files.
Our software
- BILL OS keeps records on your computer. Permissions are checked by the server, sign-in attempts are rate-limited, updates are checked against a SHA-256 checksum before installing, and backups are verified with checksums. It does not encrypt its database or backups: use disk encryption on the computer and protect backup locations.
- DINE OS checks roles on the server, prices orders from its own menu data, and keeps a safety copy before any restore.
- Installers are not code-signed yet. Check the SHA-256 checksum; see the Download and Release Policy.
Your business is responsible for the security of the computers, networks, accounts and backups the software runs on: keep Windows updated, use strong passwords and separate logins, and limit who can use the main computer.
What we do not claim
No website or software can be guaranteed free of vulnerabilities, and we do not claim absolute security. Our products have automated security tests, but they have not had an independent penetration test, and we do not hold a security certification. We will update this policy if that changes.
Report a vulnerability
If you believe you have found a security problem in this website or our software, please tell us privately first:
- email security@chamerondigital.com, or
- use the form below and choose “Security report”.
Include what you found, how to reproduce it and its likely impact. Please do not access or change other people’s data, disrupt the service, use social engineering, or publish details before we have had a reasonable chance to fix the problem. We appreciate good-faith reports that follow these rules.
A machine-readable contact is published at /.well-known/security.txt.