LegacyExodus
Security & Governance

Keep the surface small. Keep the boundaries clear.

Security information for this public website, separated from the evolving LegacyExodus analysis and modernization platform.

This website

The website is statically generated and hosted on Cloudflare Pages. It implements no sign-in, account management, payment processing, repository upload, or application database. Contact inquiries are processed through Formspree, and discovery call scheduling is handled via Cal.com. Fonts and static assets are served locally from the same origin.

Client-side code supports accessible navigation, Dark/Light theme selection, email clipboard copying, restrained motion, and explorable technical schematics. Deployment configuration enforces HTTP security headers: X-Content-Type-Options: nosniff, frame protection (frame-ancestors 'none'), referrer policies, permissions policies, and a Content Security Policy.

The Content Security Policy allows inline scripts and styles required by Astro client hydration and accessible UI primitives, with connections permitted to Cloudflare Pages, Formspree (form submissions), and Cal.com (scheduling embeds).

Engineering controls & platform isolation

The website source code includes a frozen Bun lockfile, automated static type checking, ESLint rules, automated Playwright browser tests, and dependency vulnerability audits. All service tokens and credentials remain outside the repository.

For the LegacyExodus platform itself, execution is local-first. The CLI and analysis engine execute on your own workstation or private CI infrastructure. No customer source code is transmitted to cloud servers through this marketing website.

Planned AI tool permissions, versioned context, checkpoints, compiler isolation, and independent migration verification require evaluation when implemented. Human review remains the intended acceptance authority.

Report a security concern

If you discover a vulnerability or security issue, email raitaskeen@legacyexodus.dev with “Security report” in the subject line. Please include:

  • The affected URL, route, or component.
  • Step-by-step reproduction instructions.
  • Your assessment of potential impact.

Please use minimal reproductions and avoid sending live credentials or sensitive information. While there is no published commercial bug bounty program, reports are treated with priority by our founding team.