Security
Security policy
This independent site takes security seriously. This page describes how to report issues and
what protections we apply. See also
/.well-known/security.txt
(securitytxt.org).
Responsible disclosure
If you find a vulnerability in www.escobedodecamargo.com, please report it privately so we can fix it before public disclosure.
- Email: ciber@me.lisaso.es
- Author / profile: pablolisaso.com
- Machine-readable contact: security.txt
Please include steps to reproduce, impact, and (if possible) a suggested fix. We aim to acknowledge reports within a few business days.
Scope
- In scope: https://www.escobedodecamargo.com, https://escobedodecamargo.com (redirects to www)
and the Cloudflare Worker
escobedodecamargo-2026 - Out of scope: third-party services we link to (Wikipedia, Ayuntamiento de Camargo, Cuevas Prehistóricas de Cantabria, OpenStreetMap, CDNs, email provider), social engineering, DoS only, or physical security
Controls we apply
- HTTPS with HSTS (preload-oriented max-age)
- Content-Security-Policy, frame denial, nosniff, Referrer-Policy, Permissions-Policy
- Static HTML on Cloudflare Workers (no account or session cookies of our own)
- Google Analytics 4 (gtag, G-SBQZ1TKRGL) for traffic measurement
- No account system and no write API
- Secrets, if any, stored as Worker secrets, not in git
- Public site is read-oriented
Check header grade on securityheaders.com.
Acknowledgments
We appreciate good-faith security research. With permission, we may thank reporters on this page.
Not affiliated
This site is an independent project by Pablo Lisaso. Not affiliated with Ayuntamiento de Camargo or Junta Vecinal de Escobedo.
Contact for security: ciber@me.lisaso.es · security.txt