Safer browser boundaries
Production responses are configured to narrow the contexts in which the site can run and be embedded.
HTTPS responses use HSTS to prefer secure connections on supported browsers.
Frame protections limit clickjacking and unintended embedding by other sites.
MIME sniffing protections reduce the chance that browsers reinterpret response types.
Controlled loading of content
Content Security Policy rules constrain the kinds of scripts, frames, images, and network connections the public site may load.
The policy is designed to restrict executable content to approved sources.
Third-party checkout, authentication, and telemetry connections are explicitly scoped.
High-risk browser capabilities are disabled unless the product has a specific need for them.
Need help with a security or privacy concern?
Do not include passwords, verification codes, full card numbers, or sensitive documents in your message.
Contact support
For general security and privacy questions, email support@moneykai.app.