Controls configured for this public site
The source for this static Astro/Netlify site is configured with:
- an enforced Content Security Policy that blocks unlisted external sources, objects, framing, and inline event-handler attributes; current first-party inline scripts and styles still require
unsafe-inline, so this is not a complete inline-code defense; - clickjacking protection, MIME-sniffing protection, a strict cross-origin referrer policy, a restricted browser permissions policy, and cross-origin opener isolation;
- a public security.txt contact and policy record;
- length bounds, honeypots, plain-language collection notices, and data-minimization instructions on public forms;
- analytics suppression for Global Privacy Control, Do Not Track, and the first-party browser opt-out, with advertising and Google Signals features disabled; and
- a build-time compliance/security regression check for the legal pages, disclosures, rendered proof-media references, form notices, header directives, and security.txt.
These are practical configuration controls, not a security certification, audit opinion, warranty, or promise that vulnerabilities cannot exist. Header behavior must also be verified on the deployed Netlify response after human review and deployment.
Report a suspected vulnerability
Email Costafitnessllc@gmail.com with the subject “Security report for costafitness.co.” Include the affected public URL, what you observed, safe reproduction steps, likely impact, and a way to follow up.
Do not include passwords, tokens, medical records, client information, or another person's personal data in the report. Do not access or change data that is not yours, disrupt service, use social engineering, run denial-of-service tests, or publish sensitive details before Costa Fitness has a reasonable opportunity to review them. There is no promise of a bug bounty, payment, certification, or fixed response time.
Security limits
No website or provider can be promised perfectly secure. If a public form does not request information, do not put it in the form. For privacy or deletion questions, use the process on the Privacy Notice.