Security overview
This overview describes the public courseorbit.com website. Course delivery environments require a separate, configuration-specific review.
Public-site boundary
- The public document root contains one PHP front controller and intentionally public CSS, JavaScript, and image assets.
- Templates, YAML and Markdown sources, handlers, logs, lead records, and configuration remain outside the document root.
- The public site has no login, database, shopping cart, or student course activity.
- Forms validate inputs server-side, use same-origin checks, honeypots, request-size limits, and rate limits.
Browser and server controls
The web server is configured for HTTPS transport protection, a restrictive Content Security Policy, frame blocking, MIME-type protection, limited browser permissions, no directory listing, and no server signature. Operational deployment must verify that these headers are active at the hosting edge.
Stored public-site information
Instructor requests are stored outside the web root and routed to the assigned adoptions team. First-party analytics store aggregate daily counts only. They do not retain IP addresses, user agents, form values, or persistent visitor IDs.
Incident reporting
Report a suspected security or privacy incident through the Support Center or [email protected]. Include the affected system, date and time, and a description; do not email passwords or sensitive student records.