Security
RandomZone is designed with a small attack surface. Most tools run entirely in the browser and the current platform does not require user accounts, a public database or application APIs for normal tool operation.
Security controls
- HTTPS-only production deployment
- Content Security Policy
- HTTP Strict Transport Security
- Anti-clickjacking protections
- MIME sniffing protection
- Restricted browser permissions
- Local browser processing for most tool inputs
- Web Crypto API for security-sensitive random generation
Vulnerability reporting
If you believe you have found a security issue, please report it responsibly to randomzone.fun@gmail.com. Do not intentionally access, modify or destroy data belonging to other users or disrupt the availability of the service.