Security Center

SalaryLabs is built on Cloudflare's edge network with privacy-by-default. This page explains what we collect, what we don't, and how to report vulnerabilities.

Found a security issue? Email [email protected] (response within 5 business days) or see our security.txt.

HTTP Security Headers

Every page on salarylabs.site returns the following security headers. Verified via curl -I 2026-09-18.

HeaderValueStatus
HSTS max-age=31536000; includeSubDomains; preload enabled
X-Frame-Options SAMEORIGIN (main site) / * (embed iframes) enabled
X-Content-Type-Options nosniff enabled
Referrer-Policy strict-origin-when-cross-origin enabled
Permissions-Policy camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=() enabled
CSP (main site) default-src 'self' https:; script-src restricted; object-src 'none'; base-uri 'self' enabled
CSP (embed iframes) frame-ancestors *; form-action 'self'; base-uri 'self' enabled
CSP (report-only) Pending rollout — collecting violations before enforcement pending

API Rate Limits

All Cloudflare Pages Functions enforce per-IP rate limits via KV token buckets. Standard: 60–200 req/hr for compute endpoints, 5 req/hr for LLM endpoints (cost protection).

EndpointLimitPurpose
/api/partner-event 200 req/hr per IP Prevent KV exhaustion + abuse
/api/v1/calculate 60 req/hr per IP AI agent compute cap
/api/negotiator 5 req/hr per IP LLM cost cap ($0.05/request)
/api/ai-cite Worker-side rate limit (no KV read) Free tier KV safety

Rate-limited responses include Retry-After, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset headers (per draft-ietf-httpapi-ratelimit-headers).

Third-Party Data Sharing

SalaryLabs integrates with the following third-party services. Calculator inputs (salary, tax, filing status) are never sent to analytics or advertising services.

ServicePurposeData SharedOpt-Out
Cloudflare CDN + Pages + Workers + KV + Web Analytics IP address, request URL, page type (aggregated) Built-in via Cloudflare privacy mode (always on)
NVIDIA NIM (via nim-proxy Worker) AI script generation for /tools/negotiation-script/ roleTitle, achievement, salary numbers (synthetic only — no real names) Use the static /guides/salary-negotiation-guide/ instead
Zaraz (Cloudflare) Server-side event routing for analytics Page type, tool used, audience segment (no salary data) Do Not Track browser setting honored
Google Analytics 4 (via Zaraz) Aggregate traffic measurement (no PII) Page URL, referrer, browser version (aggregated) Browser Do Not Track + consent banner
OpenAI / Anthropic / Perplexity AI agents that cite our content (via /api/ai-cite) None — they send us their visit, we record which page they cited Not applicable — this is a public citation log
Stripe (planned) Pro tier payment processing (when activated) Email + payment method only — never calculator inputs Required for paid tier

Vulnerability Disclosure Policy

We follow coordinated disclosure. Report issues via [email protected] with:

Our commitment:

We do not pursue legal action against good-faith security research. We follow the EFF Coders' Rights Project principles.

Acknowledgments

Researchers and audits that have helped us ship security improvements:

DateResearcherIssueStatus
2026-09-18 Internal audit (SalaryLab) No rate limiting on /api/partner-event — KV exhaustion risk fixed
2026-09-18 Internal audit (SalaryLab) Prompt injection vector in /api/negotiator — length cap added + pattern blocklist fixed
2026-09-18 Internal audit (SalaryLab) No security.txt — RFC 9116 disclosure policy missing fixed

More acknowledgments added as we receive and ship fixes.

What We Don't Collect

No calculator inputs to analytics

Your salary, tax, filing status, or any other form input stays in your browser. Calculators run client-side; nothing is sent to a server unless you click "Save scenario" or "Export PDF".

No cookies from analytics

Cloudflare Web Analytics is cookieless. Zaraz + GA4 are server-side routed with privacy-safe defaults. No third-party cookies are set by SalaryLabs code.

No IP logging

Cloudflare KV stores aggregated counters (e.g. partner-host × date). Raw IPs are used only for rate limiting (per-hour bucket, TTL 1hr) and never persisted.

No account creation required

All 16 calculators work without signup. Saved scenarios use localStorage only — never sent to any server.

No payment processing today

SalaryLabs is currently free. When paid tier ships (per PLAN_PREMIUM_STRATEGY.md), payment goes through Stripe — never touching our servers.

No email collection

We don't collect emails for newsletter or accounts. The only contact channel is the public [email protected] + [email protected].

Wahyu Agustiar — Independent Salary Data Researcher
Wahyu Agustiar
Independent Salary Data Researcher Published Sep 18, 2026

Maintained by the author using IRS Publication 15-T, SSA wage-base announcements, and BLS OEWS data. All calculator formulas are deterministic JavaScript — no AI inference in the numbers. Content is reviewed for accuracy when tax figures are updated annually. See Methodology · Author Profile