Trust
Conservative notes for IT, compliance, and procurement teams.
Security
- Nonce-based CSP with a per-request nonce and no unsafe-inline in script-src.
- Single CSP header from middleware as the policy source of truth.
- Strict transport security (HSTS preload) with modern TLS in transit.
- Security headers include XFO, XCTO, Referrer-Policy, and Permissions-Policy.
- Temporary session model for in-call alignment with 6-digit code joins.
- Designed for minimal collection during active session handling.
Consent and acknowledgements
Consent & Privacy Acknowledgement Flow for compliance teams.
Read the consent flowContact
For procurement requests, security questionnaires, or controls detail, contact our team.
Contact EOV6