Skip to content

Security: stackified/lockittrade-landing

.github/SECURITY.md

Security Policy

Supported versions

This is the marketing site for LockItTrade. Only the latest version on the dev branch (the default and deployment branch) is maintained.

Version Supported
Latest (dev) Yes
Older commits No

Reporting a vulnerability

Please do not open a public issue for security problems.

Instead, use GitHub's private reporting:

  1. Go to the Security tab.
  2. Click Report a vulnerability.
  3. Describe the issue, steps to reproduce, and potential impact.

You can expect an acknowledgement within a few days. Thank you for helping keep the project safe.

Notes on this project

The site is a Next.js app exported as static files (output: 'export') and served from GitHub Pages. There is no server of its own, no database, no user accounts and no payment handling. The trading tools on the page (prop firm matcher, violations tracker, compliance monitor, readiness gauge) are front-end demonstrations with no backend.

The parts that do handle visitor data or talk to third parties are:

  • Contact form - posts name, email, subject and message from the browser to a Formspree endpoint (NEXT_PUBLIC_FORMSPREE_ENDPOINT).
  • Waitlist modal - posts name and email from the browser to the systeme.io contacts API (NEXT_PUBLIC_SYSTEME_IO_API_KEY). Because this request is made client-side, any key supplied at build time is embedded in the shipped JavaScript. The GitHub Pages workflow does not set it.
  • Third-party scripts - Intercom Messenger, Vercel Analytics and FirstPromoter affiliate tracking are loaded on every page.

Reports about these integrations, exposed configuration, or cross-site scripting in the rendered pages are the most useful. The JavaScript/TypeScript is scanned by CodeQL on every push and pull request to dev.

There aren't any published security advisories