Provenance
Security, privacy and accessibility. Last verified September 23, 2026. Self-assessed; not a third-party audit or a certification.
What this site holds
mkeith.app is a personal research site: publications, datasets, and research tools such as the privacy-fine tracker and the curriculum tools. It holds no student education records, so the FERPA rules on those records have nothing here to apply to. The privacy policy says exactly what it does store.
Security controls
- Database access rules on every table reachable through the data API. Only the site’s administrator can change data or read analytics.
- Privileged key stays on the server, and the deployment holds only the credentials this site’s code uses.
- Transport and browser protections: HTTPS only with HSTS preload, a Content-Security-Policy, framing denied, MIME sniffing disabled, a strict referrer policy.
- Encryption in transit (TLS) and at rest by the database host, Supabase.
Accessibility
We aim for the Web Content Accessibility Guidelines (WCAG) 2.2 at level AA, which includes the WCAG 2.1 AA required by the U.S. Department of Justice’s 2024 ADA Title II rule and the WCAG 2.0 AA incorporated by Section 508. Automated scans find only part of what WCAG covers.
Standards we measure against
- WCAG 2.2 level AA, for accessibility.
- The OWASP Top 10 (2021), as a checklist: broken access control (A01), security misconfiguration (A05) and vulnerable components (A06) are covered by the log below.
Verification log
| Date | Check | Scope | Result |
|---|---|---|---|
| 2026-09-23 | Automated accessibility scan of the live site, after deploy | 6 public pages at desktop width; the home page at phone width | No violations on any scanned page. |
| 2026-09-23 | Leaked-password protection | Sign-in for every account | Switched on. New and changed passwords are checked against the Have I Been Pwned list of breached passwords, and known ones are refused. |
| 2026-09-23 | Database access rules, tested as a stranger's account and as an anonymous visitor | Every table reachable through the data API | Seven tables let any signed-in account read or change them. Before: a stranger who signed up could read and delete 78,207 analytics events and 2,338 company records. After: analytics are admin-only, reference data is publicly readable but only the admin can change it, and the stranger can change nothing. |
| 2026-09-23 | Credentials held by the deployment | Every environment variable on the hosting project | Twenty-three variables held credentials this site's code never uses: thirteen for a different site's database, left by an old integration, and ten for payment, survey, course-platform and AI services. All twenty-three removed. The site now holds seven: its own database's three, one AI provider key, the scheduled-job secret, a hashing salt and the site ID. |
| 2026-09-23 | API route review | Every API route | Scheduled jobs require a secret. The privacy-policy analyzer is public by design; it caps input at 50,000 characters and rate-limits by address. |
| 2026-09-23 | Dependency vulnerability audit (npm audit, production dependencies) | All production dependencies | 0 known vulnerabilities. Next.js 16.3.4. |
| 2026-09-23 | Security headers, as served | mkeith.app | HSTS with preload, Content-Security-Policy, framing denied, MIME sniffing disabled, strict referrer policy, camera, microphone and location disabled. |
| 2026-09-23 | Automated accessibility scan (axe-core, WCAG 2.0/2.1/2.2 A and AA rules) | 10 public pages at desktop width; the home page at phone width | Found: text-contrast failures on 8 pages and four unlabelled filter menus on the books page. Fixed the same day; every replacement colour measures 4.77:1 or better against each background it sits on (WCAG AA needs 4.5:1), and each menu now has a name. |
What we have not done yet
- Admin and research-tool pages beyond the ten scanned still use a light grey for some text, and no page has had a keyboard-only or screen-reader walk-through.
- Inline scripts. The Content-Security-Policy still allows them; a per-request nonce would close that.
- Independent review. Everything here is self-assessed.
Reporting a problem
Email mark_keith@byu.edu about any security issue or accessibility barrier. Please do not test against other people’s accounts or data.