Site security starts with what it does not contain

CertiShielder.com is an intentionally static showcase. No public database, no user accounts, no API exposed on this site. Less surface, fewer doors to watch — that is an architecture choice, not a slogan.

A cyber-safety choice, not only a convenience

A marketing site that behaves like a connected application stacks risks: sessions, forms, plugins, third-party scripts, poorly patched databases. Here, the public site exists to explain, document and guide. Seal Soft, Seal Web and Gateway products have their own perimeters. The showcase itself stays thin.

For a security officer, the message is simple. The digital trust we discuss in the Knowledge Center also starts with us, on the public channel: reduce what can be attacked before stacking more controls.

What we put in place

The following controls are active on the public site. They do not replace a full infrastructure assessment, but they set a readable, verifiable posture.

  • Transport. HTTPS enforced, HSTS with includeSubDomains and preload. The browser is invited never to fall back to cleartext.
  • Content. Restrictive Content-Security-Policy, centred on 'self'. No third-party CDN scripts to run the showcase. Styles and fonts self-hosted.
  • Browser frame. Anti-clickjacking (X-Frame-Options / frame-ancestors), nosniff, restrictive Referrer-Policy and Permissions-Policy, plus origin isolation (COOP / CORP) on the headers side.
  • Operational privacy. No analytics or marketing trackers on this site. CookieSafe™ manages local consent, with no send to a third-party server.
  • Minimal surface. No API, no login, no database on the showcase. Paths outside publication are refused at the server level.
  • Customer relationship. Exchanges with our teams go through CryptPeer® (Freemindtronic / FullSecure), an encrypted peer-to-peer channel. The showcase does not centralise messaging, tickets or conversation data in a public database.

What we do not claim

A well-hardened site is not “inviolable”. Posture also depends on the host, the real TLS configuration, administration accounts, backups and publishing access. We do not sell a security certification for the showcase, and we do not use the phrase “ultra secure”.

Naming the perimeter is how we stay credible. The showcase reduces surface. It does not replace an infrastructure audit, nor the security of Seal Soft, Seal Web or Gateway products, which are assessed on their own terms.

What a security expert can take away

The structuring decision is this: static by design. Then come transport and content controls consistent with that decision, without unnecessary third-party scripts, without measurement cookies. The customer relationship follows the same logic: it is handled outside the showcase, via CryptPeer®, rather than through a form or back-office exposed here. Finally, a publishing discipline: separate what is designed from what is served, refuse paths not meant for the public.

Less surface before more controls. That is the same standard we apply when we talk about digital trust. Demonstrate, limit, explain.

To go further

Read the product philosophy, the cookies policy, or write to us via CryptPeer® if you are evaluating Soft in a security framework.