Supported surface
The Utilitas hub is a static public website. It has no sign-in, account database, payment flow, public API, upload endpoint, OAuth integration, or privileged agent action. Reports should focus on behaviour reachable from https://utilitas.app or on a clearly identified linked project.
Deployment boundary
Only the generated dist/ directory is intended for publication. Source files, tests, environment files, repository history, package caches, and local tooling remain outside the deployed asset directory. Missing routes are configured to return a real 404 response.
Browser protections
The deployment includes a nonce-based strict Content Security Policy, framing protection, MIME sniffing protection, a limited referrer policy, disabled unused browser capabilities, and HTTPS transport security. Google AdSense is the only approved third-party runtime script. A Cloudflare Worker adds a fresh nonce to every script before returning HTML.
Responsible reporting
For a suspected issue, follow the private reporting guidance available from the maintainer profile on the contact page. Include the affected URL, impact, reproducible steps, and a minimal proof. Do not access other people's data, degrade availability, run broad automated scans, or publish an uncorrected vulnerability.
Project-specific reports
A vulnerability inside an individual tool should be reported through that project's security route or repository policy. Product code, file parsers, browser storage, and export behaviour are outside this hub's static browsing boundary even when the project appears in this directory.
No security guarantee
Reasonable safeguards reduce risk but cannot guarantee that software is free of defects. Keep your browser updated and retain original copies of important work before processing or exporting files with any tool.