Machine Jurisdiction · Eviulon orientation

Small attack surface, explicit boundaries

Security posture for a read-only, dependency-free PHP educational site with local assets, no accounts, no uploads, no database, and defensive headers.

Claim statusSite policySite review 2026-08-09

Application surface

The only user-controlled application input is the optional local search query. It is length-limited, normalized, escaped on output, and never executed as code or used in a database query.

Browser controls

The deployment configuration uses a self-restricted Content Security Policy, content-type protection, referrer policy, frame-ancestor restrictions, and a conservative permissions policy where Apache configuration is honored.

HTTPS boundary

Strict-Transport-Security is intentionally not asserted by this package because the repository does not prove the production HTTPS/HSTS deployment state. It should be enabled only under confirmed hosting authority.

No secrets

The repository and release package must not contain passwords, private keys, tokens, cookies, session values, production credential material, or private citizen data.

Authority boundary

Canonical Eviulon sources

These links are external canonical records or ecosystem references. MachineJurisdiction.com explains; it does not replace them.

This site-policy page relies on the local implementation rather than asserting an external Eviulon legal claim.

Next step

Continue with the authoritative record

Follow the linked canonical sources and related pages for the authoritative record.

Open source map