Data Security Policy
Last updated: September 28, 2026
This page describes how DressmakerGames.com protects the integrity, availability and confidentiality of the site and its visitors. Our security strategy is simple: the less data a website touches, the less there is to protect.
1. Encryption in Transit (HTTPS)
All traffic to dressmakergames.com is served over HTTPS with TLS encryption provided by Cloudflare. Every page, image and API request is encrypted between your browser and our servers, so credentials-free browsing cannot be intercepted or tampered with on public networks.
2. Minimal Data Footprint
- No user accounts, no passwords, no email lists — there is no credential database to breach.
- No personal information is collected, so there is nothing sensitive to leak (see our Privacy Policy).
- The only stored setting is the language preference (dm_lang) in your own browser's localStorage — under your control, never transmitted to us.
3. Blog Backend Security
The blog runs on a dedicated headless backend with two public, read-only endpoints (post list and single post). Key controls:
- Visitor-facing APIs are strictly read-only — they cannot create, modify or delete content.
- The admin panel (/admin/posts) is protected by authentication and is never linked from the public site.
- Markdown content is rendered with sanitization-friendly tooling, and article data is escaped before insertion to prevent script injection (XSS).
4. Infrastructure Providers
| Provider | Role | Security Measures |
|---|---|---|
| Cloudflare | Hosting & CDN | TLS/HTTPS, DDoS protection, edge caching |
| Google Fonts | Typefaces | Google infrastructure & standard web security |
| jsDelivr | JS library CDN | Pinned versions, SRI-friendly delivery |
5. Site Integrity
The site is version-controlled in a Git repository: every change is reviewed and attributed before it reaches production. Static pages contain no server-side code that could be exploited, and dependencies are pinned to known versions.
6. Reporting a Security Issue
If you discover a vulnerability or suspicious behaviour on this site, please let us know so we can fix it quickly. We treat all reasonable reports seriously and appreciate responsible disclosure.
7. Updates to This Policy
As the site evolves we will keep this document current. Material changes will be reflected in the date at the top of this page.
Related: Privacy Policy