Our security approach
Security is treated as an ongoing responsibility. The service uses layered safeguards for application requests, private files, and production traffic. No system is immune from risk, so controls are reviewed and improved as the service changes.
Transport safeguards
Production traffic is redirected to HTTPS. Security headers restrict framing, content-type guessing, referrer disclosure, and unnecessary access to device capabilities.
Application safeguards
- Calculator requests are validated and limited in size.
- Same-origin checks help prevent unauthorised cross-site requests.
- Request throttling helps reduce automated abuse.
- Error details are logged rather than displayed to website visitors.
Private files and configuration
Private application configuration is kept outside the public website directory in the intended deployment. Server rules block direct access to internal includes, logs, source maps, dotfiles, and other restricted files.
How you can use the website safely
- Do not enter names, account numbers, or other identifying information in scenario labels.
- Do not email passwords, financial documents, access tokens, or secret keys.
- Verify important calculator results with an appropriate lender or qualified professional.
- Contact us if you notice unexpected website behaviour.
Report a vulnerability
Email sanahosseini@gmail.com with the subject Security report, or call (02) 6622 2222. Include the affected URL, a concise description, and safe reproduction steps. Do not include real user data or publicly disclose sensitive details before there has been a reasonable opportunity to investigate. Our handling of personal information is described in the Privacy Policy.