<!-- Generated from the public HTML page by tools/generate-discovery.mjs. -->

Source: https://www.quantumsteeldesign.com/security/

Trust and transparency

# Website Security

A direct explanation of the protections used by this site and the boundaries those protections have.

Protected in transit and at the edge

The website is served over HTTPS through Cloudflare Pages. PDF Rescue keeps drawing conversion on your device, so the site does not need your drawing files in order to convert them.

Last reviewed: September 27, 2026

No website can promise absolute security. Quantum Steel Design uses layered, proportionate controls and publishes these details so visitors can make an informed decision.

## Cloudflare delivery and network protection

The production zone uses Cloudflare Full (strict) SSL mode and a minimum visitor TLS version of 1.2. DNSSEC is enabled for the zone. These settings support encrypted delivery and authenticated DNS records; they do not verify the engineering content of a page or the safety of a downloaded model.

quantumsteeldesign.com is hosted and delivered through Cloudflare Pages. Cloudflare terminates HTTPS connections at its edge and provides network-level protection, including the DDoS mitigation Cloudflare makes available to customers on all plans.

Technical references: [Cloudflare Pages documentation ↗](https://developers.cloudflare.com/pages/) and [Cloudflare DDoS protection overview ↗](https://developers.cloudflare.com/ddos-protection/about/).

## Browser security headers

The deployed site sends headers that tell supporting browsers to avoid MIME-type guessing, limit referrer information, deny camera, microphone, and geolocation access, restrict framing to the same origin, and isolate the top-level browsing context where supported.

- X-Content-Type-Options: nosniff

- Referrer-Policy: strict-origin-when-cross-origin

- Permissions-Policy: camera=(), microphone=(), geolocation=()

- X-Frame-Options: SAMEORIGIN

- Cross-Origin-Opener-Policy: same-origin

Cloudflare documents how Pages applies custom response headers in its [Pages headers guide ↗](https://developers.cloudflare.com/pages/configuration/headers/).

## Local-first drawing conversion

The browser edition of Quantum Steel PDF Rescue parses the PDF and builds the DXF on your device. The desktop edition also converts locally and can operate offline. Quantum Steel Design does not need to receive your PDF, DXF, drawing contents, or file names for conversion.

The optional public counts for likes, downloads, and conversions send small event records—not drawing files. Those records use random identifiers and one-way hashes for duplicate detection and short-term abuse control. See the [Privacy page](https://www.quantumsteeldesign.com/privacy/) for details.

## What the Cloudflare badge means

The official “Protected by Cloudflare” badge identifies Cloudflare as the website delivery and edge-security provider. It does not mean Cloudflare endorses Quantum Steel Design, has audited every line of site code, guarantees the accuracy of engineering information, or can eliminate every security risk.

## Report a security concern

If you believe you found a vulnerability or unsafe behavior, use the [contact page](https://www.quantumsteeldesign.com/contact/?source=security). Include the affected URL, what you observed, steps to reproduce it, and a safe way to reach you. Do not access data that is not yours, disrupt the service, or publicly disclose a suspected issue before Quantum Steel Design has had a reasonable opportunity to review it.

Automated security contacts can read the published [security.txt disclosure file](https://www.quantumsteeldesign.com/.well-known/security.txt). Broader project-data, automation, and human-review principles are documented in the [Trust Center](https://www.quantumsteeldesign.com/trust/).
