Transparency Report

How this website is secured

We audit other organisations' privacy and security practices. It would be contradictory not to hold ourselves to the same standard. This page documents exactly what mtecsoft.com does — and does not do — with your visit.

What we do not collect

Client-side analytics None

No Google Analytics, no Matomo, no Plausible, no Fathom, no pixel trackers. Zero JavaScript analytics of any kind.

Cookies Zero

This website sets no cookies — neither first-party nor third-party. No consent banner is required because there is nothing to consent to.

Third-party scripts None

No external JavaScript is loaded. Fonts are self-hosted. The only outbound request your browser makes is to this server.

What we do collect

Apache access logs 7-day retention

Standard server access logs record IP address, timestamp, requested URL, HTTP status code, user agent, and referrer. These are used exclusively for security diagnostics and attack detection. IP addresses are not linked to any profile or identifier. Logs are automatically purged after 7 days.

HTTP security headers

Content-Security-Policy Enforced

default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self'; base-uri 'self'; form-action 'none'; frame-ancestors 'none'

Strict-Transport-Security Enforced

max-age=31536000; includeSubDomains — all connections forced to HTTPS with a one-year HSTS policy.

X-Frame-Options DENY

This site cannot be embedded in frames or iframes. Prevents clickjacking attacks.

Referrer-Policy Enforced

strict-origin-when-cross-origin — referrer data is not leaked to external domains.

Permissions-Policy Enforced

geolocation=(), microphone=(), camera=(), payment=() — browser APIs that could compromise privacy are explicitly disabled.

X-Content-Type-Options nosniff

Prevents MIME-type sniffing attacks.

Vulnerability reporting

If you identify a security issue with this website, please contact disclosure@mtecsoft.com. Our security.txt file is published at /.well-known/security.txt in accordance with RFC 9116.