Security Statement
Last updated: 1 August 2026 · Applies to: nativework.org
For security enquiries or to report a vulnerability: info@nativework.org
In short
This page explains how we protect information.
- This website holds nothing about you. There is no database behind it, no login, and no form that sends anything to us. It is a set of fixed pages.
- In transit: everything is encrypted between your browser and the site.
- Where it runs: on certified hosting inside the European Union.
- How we build: passwords and keys are never stored in our code, and our software libraries are checked continuously.
If you find a security problem, please tell us at info@nativework.org. We will reply within two working days, and we will not take legal action against anyone researching in good faith.
This is the baseline. NativeWork services that hold accounts or payments publish their own extra page describing those protections.
This summary is here to help you understand the statement. The full text below is what applies.
What this covers
This is the baseline security statement for NativeWork. It covers Centipod’s security practice and the public website at nativework.org.
Separate services publish an addendum. A service that holds accounts, conversations or payments states its own controls — isolation between accounts, encryption at rest, retention, subprocessors — in an addendum alongside this statement.
The public website
The site is static and holds no personal data. There is no database behind it, no account, no login and no form that submits to us. Pages are pre-built files served from a content delivery network.
This is a deliberate choice rather than a stage we have not yet grown out of. The material is meant to be read; nothing about reading it requires us to know who you are.
Transport. TLS 1.3 with HTTP Strict Transport Security enforced. All HTTP requests redirect to HTTPS. No traffic to or from the site is unencrypted.
Response headers. Content Security Policy, frame denial, MIME-sniffing protection and referrer restriction on every response.
Cookies. None. No analytics, no advertising, no third-party tracking.
Hosting. Served by a provider holding ISO 27001:2022 and SOC 2 Type 2, from EU regions. Transfers of operational metadata outside the EU are governed by Standard Contractual Clauses and the EU–US Data Privacy Framework.
How we build
Secrets. Held in an encrypted environment store, never in source control. The repository has secret scanning and push protection enabled. Secrets are rotated on any suspicion of exposure.
Dependencies. Scanned continuously, and the dependency tree kept deliberately small. The website itself has no runtime dependencies.
Access. Administrative access to production is limited to named individuals and protected by multi-factor authentication.
Reporting a vulnerability
Email info@nativework.org. We will acknowledge within two working days and keep you informed.
We ask that you give us reasonable opportunity to fix an issue before disclosing it, and that you avoid accessing other people’s data while testing. We will not pursue legal action against good-faith research conducted within those bounds.
Incidents
If a breach affects your personal data, we will notify the Dutch supervisory authority within 72 hours as Article 33 requires, and notify you directly where the risk to your rights is high.