Security
Clear security boundaries for a small, serious system.
Security claims should be specific and supportable. This page describes the website’s current operational boundaries without claiming certification or absolute protection.
Last updated: 26 August 2026
Public and private separation
The public website and intake path are separated from the private Operations and Projects environments. Internal surfaces use their own access boundary and are excluded from public search discovery.
Inquiry processing
Website inquiries are validated by a server-side function before a lead record and email queue documents are created. The function limits accepted methods and fields, checks allowed origins, caps submitted text, and includes a hidden bot-trap field.
Secrets and service access
Mail delivery credentials are stored through Google Cloud Secret Manager. Cloud workloads use dedicated service identities and private service-to-service authentication where configured. Credentials are not embedded in public browser code.
Important limits
No internet service can promise complete security. Keyway does not claim that this website has received an external penetration test, security certification, or compliance audit unless a future published statement explicitly documents one.
Responsible disclosure
If you believe you have found a vulnerability, report it privately with the affected URL, reproduction steps, potential impact, and a safe way to contact you. Do not access data that is not yours, disrupt service, or publicly disclose an unresolved issue.
- Security contact: fabien@keyway-studio.com