SECURITY

Security is a release requirement, not a badge.

This page documents the controls currently shipped with e2massociates.com and the Expansion Passport, plus how to report a potential vulnerability.

Privacy model · Updated 2026-09-17E2M Expansion Passport

Browser and transport controls

The production package enforces HTTPS transport hardening, clickjacking protection, content-type protection, a restrictive permissions policy and a Content Security Policy that limits active resources and form submissions to the E2M origin. The current static architecture still requires inline script/style allowances; that limitation is explicit rather than hidden.

Local-first Passport design

Passport planning data remains in the browser by default. The analytics event buffer is session-only, bounded, cookie-free and has no network transport. Execution context is transmitted only after an explicit form submission, and trust-governance removes acquisition/visit metadata from that handoff.

Third-party exposure

No third-party analytics SDK or externally hosted JavaScript is embedded in the release package. External services are reached through user-initiated links rather than silent trackers or embedded frames.

Form and data-flow controls

Forms use first-party submission endpoints and honeypot fields where applicable. The Passport execution handoff applies an explicit allowlist/minimization policy and publishes a machine-readable data-flow manifest in the release.

Report a potential vulnerability

Send a concise report to contact@e2massociates.com with the affected URL, reproduction steps, impact and any supporting evidence. Please avoid accessing or changing data that is not yours, degrading service, or using social engineering. E2M does not currently publish a bug-bounty program.

Scope and limitations

No website can guarantee absolute security. These controls describe the shipped release and are reviewed as the product changes. The canonical disclosure endpoint is /.well-known/security.txt.

Privacy & data

How E2M handles website inquiries and Expansion Passport data, including local storage, analytics boundaries and execution-request submissions.

Privacy & data →

Last updated: September 17, 2026