Legal
Security
Last updated August 16, 2026
What this page is
A public record of how this website is protected. It is not a consulting product and not a claim of certification. If you find a vulnerability, tell us.
Transport and headers
The site is served over HTTPS. Responses include HSTS, a content security policy, clickjacking protection, and a locked-down permissions policy.
Diagnostic form
Submissions are length-capped, rate-limited, and filtered for automated abuse. Cloudflare Turnstile must pass before a request is accepted in production.
Notifications go to Cashlyn over Resend. We do not write full form payloads to application logs in production.
What we collect
Name, work email, company, title, optional revenue range, and whatever you write about the aging. Plus standard request metadata used to run and protect the form.
We do not sell this information. We do not use it for spray-and-pray marketing.
Report a problem
Email hello@cashlyn.com with enough detail to reproduce. Do not run destructive tests against the live site. We will acknowledge in good faith.