Public website security posture and deployment responsibilities.
The package is static by default; production deployments must configure HTTPS, CSP, HSTS, monitoring and a reviewed form backend if enabled.
This page describes the public website policy. For Trusted ThingID service controls, see Service Security & Resilience →
No production secrets belong in public source, downloads, browser storage or forms.