Observability Active
Sentry browser SDK Loader Script with full integration suite. Events route to slatech-sites project; crash-free session rate >99.9% rolling 30-day.
GDPR Compliant
DPA on request. Lead-form retention 24 months unless contracted otherwise. No third-party advertising trackers on lead pages.
Security Headers Active
HSTS (1y + preload), X-Content-Type-Options nosniff, X-Frame-Options SAMEORIGIN, X-Powered-By + X-AspNet-Version stripped.
CSP Report-Only
Content-Security-Policy in Report-Only mode with allowlist published in header.
Cookies Hardened
Secure; HttpOnly; SameSite=Lax session cookies. No advertising cookies.