Security
Last updated 2026-10-02
The short version
This site is static pages with nothing to log in to and nothing to submit. If you find a security problem here or in anything we publish, email ask@collapseindex.org with "Security" in the subject.
This site
- No accounts, no forms, no cookies. There is nothing to sign in to and nothing you type is sent anywhere. The early access form is hosted by Google, not here.
- HTTPS only. Every page is served over HTTPS, and browsers are told to keep it that way.
- Locked-down pages. A content security policy lets pages load scripts, styles and images only from this site, fonts only from Google Fonts on a few older pages, and video only from YouTube's no-cookie player, after you press play. Pages can't be framed by other sites.
- No secrets in the code. Before a release we check the site's code and its history for keys and passwords, and check its dependencies for known problems.
HOBO
- Private installs run on your own hardware. Your requests stay with you, and an install sends us nothing unless you choose to.
- The HOBO API isn't open yet. Before it opens, this page will say how requests are protected, how long anything is kept, and who can see it.
- Its weights aren't published. Every training row is listed with its source and license, so you can still see what went into it. See Data and licensing.
Reporting a problem
Email ask@collapseindex.org with "Security" in the subject. Tell us what you found, where, and how to reproduce it. We'll reply, work on a fix, and tell you when it's done. Our contact details are also at /.well-known/security.txt.
If you look for problems in good faith, we won't pursue you for it. Please:
- Only test against your own data and access. Don't read, change or delete anyone else's.
- Don't overload the site or try to take it down, and don't use social engineering or phishing.
- Give us a reasonable time to fix a problem before you share it publicly.