Security
Last updated 3 September 2026
This is a small practice, so the security posture is deliberately simple: hold as little as possible, and let specialists handle the parts that carry real risk.
Payments
Card data never touches this site. Checkout is handed to a PCI DSS Level 1 certified payment processor, and what returns is a transaction reference plus the email address to deliver to. No card number, expiry or security code is transmitted to, processed by, or stored on wayoffitness.net.
Data in transit and at rest
The whole site is served over TLS with HTTP Strict Transport Security enforced. There is no customer-facing login, no member database and no stored payment method, which removes most of the categories of breach that matter.
Infrastructure
Static content and serverless functions run on SOC 2 Type II certified cloud infrastructure behind a web application firewall with rate limiting on every endpoint that accepts input. Email delivery runs through a SOC 2 Type II certified provider.
Application
A Content Security Policy restricts script and frame sources. Framing is denied, MIME sniffing is disabled, and referrer information is limited. Server errors return a reference identifier rather than a stack trace.
Reporting a vulnerability
Reports are welcome and will not be met with legal threats where testing is made in good faith, stays within this domain, avoids degrading the service, and does not access data belonging to anyone else. Automated scanning at volume is not good-faith testing.
Email irvin@wayoffitness.net with steps to reproduce. Acknowledgement inside five business days. Machine-readable contact details are published at /.well-known/security.txt per RFC 9116.
There is no paid bug bounty. Researchers who report a valid issue are credited at /security/thanks if they want to be.