Provenance

Security, privacy and accessibility. Last verified September 23, 2026. Self-assessed; not a third-party audit or a certification.

What this site holds

mkeith.app is a personal research site: publications, datasets, and research tools such as the privacy-fine tracker and the curriculum tools. It holds no student education records, so the FERPA rules on those records have nothing here to apply to. The privacy policy says exactly what it does store.

Security controls

  • Database access rules on every table reachable through the data API. Only the site’s administrator can change data or read analytics.
  • Privileged key stays on the server, and the deployment holds only the credentials this site’s code uses.
  • Transport and browser protections: HTTPS only with HSTS preload, a Content-Security-Policy, framing denied, MIME sniffing disabled, a strict referrer policy.
  • Encryption in transit (TLS) and at rest by the database host, Supabase.

Accessibility

We aim for the Web Content Accessibility Guidelines (WCAG) 2.2 at level AA, which includes the WCAG 2.1 AA required by the U.S. Department of Justice’s 2024 ADA Title II rule and the WCAG 2.0 AA incorporated by Section 508. Automated scans find only part of what WCAG covers.

Standards we measure against

  • WCAG 2.2 level AA, for accessibility.
  • The OWASP Top 10 (2021), as a checklist: broken access control (A01), security misconfiguration (A05) and vulnerable components (A06) are covered by the log below.

Verification log

Security and accessibility checks, newest first
DateCheckScopeResult
2026-09-23Automated accessibility scan of the live site, after deploy6 public pages at desktop width; the home page at phone widthNo violations on any scanned page.
2026-09-23Leaked-password protectionSign-in for every accountSwitched on. New and changed passwords are checked against the Have I Been Pwned list of breached passwords, and known ones are refused.
2026-09-23Database access rules, tested as a stranger's account and as an anonymous visitorEvery table reachable through the data APISeven tables let any signed-in account read or change them. Before: a stranger who signed up could read and delete 78,207 analytics events and 2,338 company records. After: analytics are admin-only, reference data is publicly readable but only the admin can change it, and the stranger can change nothing.
2026-09-23Credentials held by the deploymentEvery environment variable on the hosting projectTwenty-three variables held credentials this site's code never uses: thirteen for a different site's database, left by an old integration, and ten for payment, survey, course-platform and AI services. All twenty-three removed. The site now holds seven: its own database's three, one AI provider key, the scheduled-job secret, a hashing salt and the site ID.
2026-09-23API route reviewEvery API routeScheduled jobs require a secret. The privacy-policy analyzer is public by design; it caps input at 50,000 characters and rate-limits by address.
2026-09-23Dependency vulnerability audit (npm audit, production dependencies)All production dependencies0 known vulnerabilities. Next.js 16.3.4.
2026-09-23Security headers, as servedmkeith.appHSTS with preload, Content-Security-Policy, framing denied, MIME sniffing disabled, strict referrer policy, camera, microphone and location disabled.
2026-09-23Automated accessibility scan (axe-core, WCAG 2.0/2.1/2.2 A and AA rules)10 public pages at desktop width; the home page at phone widthFound: text-contrast failures on 8 pages and four unlabelled filter menus on the books page. Fixed the same day; every replacement colour measures 4.77:1 or better against each background it sits on (WCAG AA needs 4.5:1), and each menu now has a name.

What we have not done yet

  • Admin and research-tool pages beyond the ten scanned still use a light grey for some text, and no page has had a keyboard-only or screen-reader walk-through.
  • Inline scripts. The Content-Security-Policy still allows them; a per-request nonce would close that.
  • Independent review. Everything here is self-assessed.

Reporting a problem

Email mark_keith@byu.edu about any security issue or accessibility barrier. Please do not test against other people’s accounts or data.