Security overview

This overview describes the public courseorbit.com website. Course delivery environments require a separate, configuration-specific review.

Public-site boundary

  • The public document root contains one PHP front controller and intentionally public CSS, JavaScript, and image assets.
  • Templates, YAML and Markdown sources, handlers, logs, lead records, and configuration remain outside the document root.
  • The public site has no login, database, shopping cart, or student course activity.
  • Forms validate inputs server-side, use same-origin checks, honeypots, request-size limits, and rate limits.

Browser and server controls

The web server is configured for HTTPS transport protection, a restrictive Content Security Policy, frame blocking, MIME-type protection, limited browser permissions, no directory listing, and no server signature. Operational deployment must verify that these headers are active at the hosting edge.

Stored public-site information

Instructor requests are stored outside the web root and routed to the assigned adoptions team. First-party analytics store aggregate daily counts only. They do not retain IP addresses, user agents, form values, or persistent visitor IDs.

Incident reporting

Report a suspected security or privacy incident through the Support Center or [email protected]. Include the affected system, date and time, and a description; do not email passwords or sensitive student records.