Local processing boundary
Public test JavaScript has no endpoint for sending key content, pointer coordinates, media frames, audio samples, snapshots, gamepad IDs or controller inputs. Anonymous event collection accepts only a small allowlist and stores aggregate counters.
Application security
PDO prepared statements, password hashing, CSRF tokens, secure session cookies, output escaping and administrator audit logs protect the management surface. Production errors do not expose database details or stack traces.
Browser protections
HTTPS enables protected media APIs. HSTS, Content Security Policy, Referrer Policy, nosniff, frame restrictions and Permissions Policy reduce common browser risks. Fullscreen and media permissions remain user controlled.
Advertising boundary
Ads are disabled by default. When enabled, language eligibility, page eligibility, consent and publisher configuration are checked before loading. Test pads, permission prompts, fullscreen routes, results, search, errors and admin screens remain ad-free.