← Back to trust

Security

A simple security posture for a site that should stay light.

Security should follow from simplicity, clear ownership, and an unwillingness to expose more infrastructure than the site actually needs.

Keep the surface small

Wiyc’s public sites should remain mostly static and operationally narrow by default. The smaller the exposed surface, the easier it is to reason about risk.

Shared services should stay bounded

Where shared infrastructure is used across entities, such as forms or waitlists, access should remain segmented and operational ownership should stay clear.

Security is an ongoing posture

This page will become more concrete as Wiyc’s public systems become more concrete. The standard is not a performance of certainty, but an actual habit of reducing avoidable risk.