Security Center
SalaryLabs is built on Cloudflare's edge network with privacy-by-default. This page explains what we collect, what we don't, and how to report vulnerabilities.
Found a security issue? Email [email protected] (response within 5 business days) or see our security.txt.
HTTP Security Headers
Every page on salarylabs.site returns the following security headers. Verified via curl -I 2026-09-18.
| Header | Value | Status |
|---|---|---|
HSTS | max-age=31536000; includeSubDomains; preload | enabled |
X-Frame-Options | SAMEORIGIN (main site) / * (embed iframes) | enabled |
X-Content-Type-Options | nosniff | enabled |
Referrer-Policy | strict-origin-when-cross-origin | enabled |
Permissions-Policy | camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=() | enabled |
CSP (main site) | default-src 'self' https:; script-src restricted; object-src 'none'; base-uri 'self' | enabled |
CSP (embed iframes) | frame-ancestors *; form-action 'self'; base-uri 'self' | enabled |
CSP (report-only) | Pending rollout — collecting violations before enforcement | pending |
API Rate Limits
All Cloudflare Pages Functions enforce per-IP rate limits via KV token buckets. Standard: 60–200 req/hr for compute endpoints, 5 req/hr for LLM endpoints (cost protection).
| Endpoint | Limit | Purpose |
|---|---|---|
/api/partner-event | 200 req/hr per IP | Prevent KV exhaustion + abuse |
/api/v1/calculate | 60 req/hr per IP | AI agent compute cap |
/api/negotiator | 5 req/hr per IP | LLM cost cap ($0.05/request) |
/api/ai-cite | Worker-side rate limit (no KV read) | Free tier KV safety |
Rate-limited responses include Retry-After, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset headers (per draft-ietf-httpapi-ratelimit-headers).
Third-Party Data Sharing
SalaryLabs integrates with the following third-party services. Calculator inputs (salary, tax, filing status) are never sent to analytics or advertising services.
| Service | Purpose | Data Shared | Opt-Out |
|---|---|---|---|
| Cloudflare | CDN + Pages + Workers + KV + Web Analytics | IP address, request URL, page type (aggregated) | Built-in via Cloudflare privacy mode (always on) |
| NVIDIA NIM (via nim-proxy Worker) | AI script generation for /tools/negotiation-script/ | roleTitle, achievement, salary numbers (synthetic only — no real names) | Use the static /guides/salary-negotiation-guide/ instead |
| Zaraz (Cloudflare) | Server-side event routing for analytics | Page type, tool used, audience segment (no salary data) | Do Not Track browser setting honored |
| Google Analytics 4 (via Zaraz) | Aggregate traffic measurement (no PII) | Page URL, referrer, browser version (aggregated) | Browser Do Not Track + consent banner |
| OpenAI / Anthropic / Perplexity | AI agents that cite our content (via /api/ai-cite) | None — they send us their visit, we record which page they cited | Not applicable — this is a public citation log |
| Stripe (planned) | Pro tier payment processing (when activated) | Email + payment method only — never calculator inputs | Required for paid tier |
Vulnerability Disclosure Policy
We follow coordinated disclosure. Report issues via [email protected] with:
- Clear reproduction steps (PoC if possible)
- Impact assessment (data leak / DoS / auth bypass / etc.)
- Your preferred credit name + email (optional, for our Hall of Fame)
Our commitment:
- Acknowledge within 5 business days
- Triage within 10 business days (severity rating + fix plan)
- Fix critical/high within 30 days
- Disclose mutually-agreed timeline after fix (default: 90 days)
- Credit reporters in our Hall of Fame (anonymity honored if requested)
We do not pursue legal action against good-faith security research. We follow the EFF Coders' Rights Project principles.
Acknowledgments
Researchers and audits that have helped us ship security improvements:
| Date | Researcher | Issue | Status |
|---|---|---|---|
| 2026-09-18 | Internal audit (SalaryLab) | No rate limiting on /api/partner-event — KV exhaustion risk | fixed |
| 2026-09-18 | Internal audit (SalaryLab) | Prompt injection vector in /api/negotiator — length cap added + pattern blocklist | fixed |
| 2026-09-18 | Internal audit (SalaryLab) | No security.txt — RFC 9116 disclosure policy missing | fixed |
More acknowledgments added as we receive and ship fixes.
What We Don't Collect
No calculator inputs to analytics
Your salary, tax, filing status, or any other form input stays in your browser. Calculators run client-side; nothing is sent to a server unless you click "Save scenario" or "Export PDF".
No cookies from analytics
Cloudflare Web Analytics is cookieless. Zaraz + GA4 are server-side routed with privacy-safe defaults. No third-party cookies are set by SalaryLabs code.
No IP logging
Cloudflare KV stores aggregated counters (e.g. partner-host × date). Raw IPs are used only for rate limiting (per-hour bucket, TTL 1hr) and never persisted.
No account creation required
All 16 calculators work without signup. Saved scenarios use localStorage only — never sent to any server.
No payment processing today
SalaryLabs is currently free. When paid tier ships (per PLAN_PREMIUM_STRATEGY.md), payment goes through Stripe — never touching our servers.
No email collection
We don't collect emails for newsletter or accounts. The only contact channel is the public [email protected] + [email protected].