Trust
Last checked 15 September 2026 · security score 99/100
How your data is handled
BookBlume Publications collects only what you send: a message through the contact form, or an address you give to a newsletter. It is never sold or shared for advertising. You can ask what is held about you, and ask for it to be removed, using the contact details on this site.
Consent
Nothing optional runs before you agree to it. Analytics and any similar measurement stay switched off until you accept them, and you can change your mind at any time.
How the site is secured
- Every page is served over HTTPS, with HSTS on the live domain so browsers refuse an insecure connection.
- A Content-Security-Policy is enforced, so the browser runs only the code and connects only to the services this site actually uses.
- Hardened response headers: no MIME sniffing, a strict referrer policy, and powerful browser features (camera, microphone, location) switched off.
- Private data sits behind row-level security in the database, so one site can never read another’s, and the public can read only what is meant to be public.
- Dependencies are scanned for known vulnerabilities and the code is scanned for leaked secrets on every change.
- The parts that take input from the open internet sit behind a managed web application firewall.
Where it runs
- Cloudflare serves and protects the site at the edge (SOC 2 Type II).
- Fly.io runs the build and publishing service (SOC 2 Type II).
- Supabase stores site data in the EU, London region (SOC 2 Type II).
Reporting a concern
Security researchers can find our contact details and policy at/.well-known/security.txt. For anything else, use the contact details on this site.