Bounded claims
Conceptual workflow states are labelled. The site does not present a mock action as proof of a live send or provider result.
Security / evidence over theatre
What the SynthCrew public preview can verify today, what remains unconfigured, and how the product boundary treats agent actions.
This is a security posture summary for the public SynthCrew website. It separates controls implemented in the source from controls that require the final host, domain, providers, and operational owners.
Conceptual workflow states are labelled. The site does not present a mock action as proof of a live send or provider result.
The public website uses static HTML/CSS, a small local navigation script, and a narrow server-side request endpoint; no credential, provider token, or analytics SDK is embedded in the client.
Build, secret scan, route validation, accessibility, browser, and Lighthouse checks are reproducible before a release candidate is accepted.
HTTPS, HSTS, CSP delivery, DNS, access control, deploy provenance, backups, uptime alerts, mailbox security, incident response, dependency updates, and provider permissions belong to the final deployment and operations runbook. The contact endpoint also requires provider delivery, rate-limit, log-retention, and alert ownership review; these are not silently claimed by source alone.
For a private-preview security question, email [email protected]. Do not include exploit payloads, secrets, or personal data in the initial message.
Continue with context
The public site is designed for careful evaluation. If you need product-specific context, request access rather than treating this page as an authenticated surface.
Request access