Local assets
Product media are served locally; no external font CDN is used.
We describe confirmed controls precisely and avoid unsupported certification, availability or compliance claims.
Product media are served locally; no external font CDN is used.
Google Analytics loads only after active consent.
Forms are validated on the server and protected against header injection.
Honeypot, CSRF, timing checks, rate limits, duplicate detection and optional Turnstile.
Lead data is stored in protected server-side storage and is not passed to analytics.
A server-side purge routine supports defined deletion periods.
Hosting location, encryption, backups, role models, logging, deletion concepts and availability must be confirmed against the production environment before publication as contractual claims.
The website deliberately avoids phrases such as “100% secure”, “fully court-proof” or “guaranteed availability”.
Security-related observations can be sent to frank@schadennetzwerk.com. The package also contains a security.txt file for technical contact discovery.