Cashlyn

Legal

Security

Last updated August 16, 2026

What this page is

A public record of how this website is protected. It is not a consulting product and not a claim of certification. If you find a vulnerability, tell us.

Transport and headers

The site is served over HTTPS. Responses include HSTS, a content security policy, clickjacking protection, and a locked-down permissions policy.

Diagnostic form

Submissions are length-capped, rate-limited, and filtered for automated abuse. Cloudflare Turnstile must pass before a request is accepted in production.

Notifications go to Cashlyn over Resend. We do not write full form payloads to application logs in production.

What we collect

Name, work email, company, title, optional revenue range, and whatever you write about the aging. Plus standard request metadata used to run and protect the form.

We do not sell this information. We do not use it for spray-and-pray marketing.

Report a problem

Email hello@cashlyn.com with enough detail to reproduce. Do not run destructive tests against the live site. We will acknowledge in good faith.