Security
Security
Last updated 26 July 2026.
How this site is built to be safe
HTTPS is enforced everywhere (HSTS), a strict Content-Security-Policy limits what can run, and no third-party scripts, trackers, or tag managers load at all. Standard protective headers are in place (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy). The contact form uses a hidden spam-trap field rather than a tracking-based CAPTCHA.
Found a problem?
If you spot a security issue on handbuilt.works, I'd genuinely like to know. Email trevor@handbuilt.works with the details — I read every message myself and I'll respond. Please give me a fair chance to fix it before sharing it publicly.