Public surface
Core public routes are intentionally unauthenticated. Health responses are minimal and must not expose secrets, stack traces, environment values, or dependency inventories. The Next.js powered-by header is disabled.
Trust
Last updated: August 2026
Core public routes are intentionally unauthenticated. Health responses are minimal and must not expose secrets, stack traces, environment values, or dependency inventories. The Next.js powered-by header is disabled.
Secrets are not committed to the repository. Production configuration is managed on the host with restricted permissions. Environment templates in the repository contain non-secret examples only.
The live company platform on futvara.com runs behind TLS with a reverse proxy, containerized application deployment, host firewall practices, and operational monitoring documented in the repository. Database services are not exposed as a public surface.
This page does not publish internal network diagrams, credential stores, backup encryption identities, or detailed fail2ban/SSH hardening runbooks. High-level practices may be summarized; operational secrets and exploit detail are out of scope for public disclosure.
Futivara does not claim ISO 27001, SOC 2, or similar certifications on this site. If certifications are obtained later, they will be listed only with accurate scope and dates.
Service liveness for the web application is published at the public health endpoints `/health` and `/api/health`.
Authentication, authorization, rate limiting for sensitive endpoints, and customer data controls are planned for later platform phases. They are not part of the current public website foundation and are not described here as complete.
Security-related reports can be sent to contact@futvara.com. Prefer the “Security” inquiry category on the contact page. Include enough detail to reproduce the issue; do not include unrelated personal data.
Please allow reasonable time for assessment before public disclosure of a newly reported vulnerability.