Security
Security and responsible reporting.
Last updated: October 2, 2026. This page describes the controls appropriate to the current public static site and the planned owner platform.
Current public-site controls
- HTTPS delivery through Vercel and Cloudflare-managed DNS.
- Content Security Policy, frame blocking, MIME-sniffing protection, referrer policy, restricted browser permissions, and cross-origin isolation headers.
- No passwords, payment cards, government IDs, or private calendar feeds are requested by the public listing cards.
- Private calendar URLs are treated as secrets and must not be published or logged.
- A vulnerability-reporting contact is published at /.well-known/security.txt.
Planned dashboard controls
- Verified owner accounts with email verification and role-based access.
- Admin approval before publication and an audit trail for review changes.
- Row-level owner isolation so an owner cannot access another owner’s data.
- Encrypted calendar-feed storage, revocation, stale-feed alerts, and secret redaction from logs.
- Rate limits, bot protection, input validation, malware-safe document handling, backups, monitoring, and incident response.
Report a vulnerability
Please email hello@cebuoktravel.com with the affected URL, steps to reproduce, impact, and your contact details. Do not include passwords, live payment details, identity documents, or exposed calendar URLs. Please allow reasonable time for investigation before public disclosure.
Important limitation
This page is not a guarantee that the service is secure or compliant. The owner portal, database, payment flow, data-retention controls, and incident-response process must be implemented and tested before the service accepts sensitive information or guest funds.