MEDIUM
Under the bonnet: an outside security audit, answered
An outside audit of the site came back with five findings and four are answered in this build: the Strava cards on fell pages are built from data rather than pasted in as HTML; withdrawing consent for Instagram now cancels any embed still waiting to load, and the choice expires after 180 days as the policy says; the privacy page describes what the site actually stores, the newsletter included; and there is a security.txt so anyone who finds a problem knows where to write. The fifth, a content security policy, goes out in report-only mode first. Four new checks run on every push so none of it can quietly come back. Privacy & cookies →