Encrypted delivery
The public site is delivered over HTTPS through Cloudflare, with modern TLS settings and HTTPS enforcement at the edge.
Security is part of how Big Boom Creations builds and operates public systems. We use layered controls, minimize unnecessary exposure, and provide a clear path for responsible vulnerability reports.
The public Big Boom Creations site uses a small attack surface and a defense-in-depth approach appropriate to its current functionality.
The public site is delivered over HTTPS through Cloudflare, with modern TLS settings and HTTPS enforcement at the edge.
Content Security Policy, frame protections, referrer controls, permissions restrictions, and related headers reduce unnecessary browser capabilities.
The current public site avoids public accounts, payment processing, open submissions, and unnecessary third-party scripts while those features are not needed.
Projects that are not ready for public access are intended to use access controls rather than relying on hidden links or obscurity.
Please report suspected vulnerabilities to security@bigboomcreations.net. Useful reports include the affected URL or system, what you observed, steps to reproduce it, and enough technical detail for us to investigate.
When testing, please avoid destructive activity, privacy violations, social engineering, denial-of-service activity, or accessing data that does not belong to you. Stop testing if you encounter sensitive information and report it instead.
As Big Boom Creations adds public applications, accounts, APIs, downloads, payments, or other higher-risk functionality, those systems may receive additional controls, policies, and product-specific security guidance. This page describes the current public website baseline rather than promising that every future product will share an identical architecture.