Security

RandomZone is designed with a small attack surface. Most tools run entirely in the browser and the current platform does not require user accounts, a public database or application APIs for normal tool operation.

Security controls

  • HTTPS-only production deployment
  • Content Security Policy
  • HTTP Strict Transport Security
  • Anti-clickjacking protections
  • MIME sniffing protection
  • Restricted browser permissions
  • Local browser processing for most tool inputs
  • Web Crypto API for security-sensitive random generation

Vulnerability reporting

If you believe you have found a security issue, please report it responsibly to randomzone.fun@gmail.com. Do not intentionally access, modify or destroy data belonging to other users or disrupt the availability of the service.