Withstead.me · Version 1 · September 17, 2026 · technical details verified September 17, 2026
Security
This page describes how Withstead handles security and data, in specific terms, with the limits stated. It is written the way we would want to read one: what is true now, what is not built yet, and what we are not claiming.
The short version: this website is a static site behind Cloudflare with a hardened content-security policy, no cookies and no third-party trackers; the launch list is bot-checked, rate-limited, and deleted after 90 days; calls are not open yet, and when they open, no call audio is recorded by us.
The website and launch list, today
- Encrypted transport. Pages are served over HTTPS only, through Cloudflare. There is no plain-HTTP version of the site to reach.
- Strict content rules. Every page is served with a content-security policy that allows scripts only from Withstead's own origin and Cloudflare's challenge service, forbids framing the site anywhere, forbids form submission to any destination, and blocks object and base-tag injection. Also sent on every response: X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: no-referrer, and a permissions policy that disables camera, microphone, and geolocation.
- No cookies, no trackers, no ad tech. The site sets no cookies and loads no third-party analytics beyond Cloudflare's own cookieless aggregate reporting. There is no advertising pixel, no session replay, and no cross-site identifier. Nothing follows you off this site.
- The illustration does not collect anything. The fictional call demo runs in your browser from facts in the page. It does not submit or save what you click.
- The launch list is defended and short-lived. A submission is verified with Cloudflare Turnstile before any record is written. Repeated submissions are limited using a keyed fingerprint derived from the request, and the raw IP address is not what we store. One value we do store is your email address, an optional first name, and the record of your consent — and a scheduled cleanup deletes signup records after 90 days, along with expired rate-limit records.
Email to withstead.me
Mail for the domain is handled by Cloudflare Email Routing. SPF is published for the domain. DMARC is published in monitoring-only mode (p=none), which means mail sent as withstead.me is measured but not yet rejected or quarantined when it fails authentication. We treat moving DMARC to an enforcing policy as open work, and we are telling you that here rather than describing the domain as fully protected.
The product, when access opens
Calling is not available today. These are the design commitments for the phone companion, and we will republish this page with the same kind of verification detail once access opens:
- No call recording or storage by us. We do not record calls, and we do not keep call audio. To work at all, live audio passes in real time through a telephony provider and a language-model provider.
- The transcript is temporary. A text transcript exists only long enough to build your post-call summary. It is deleted when you approve the summary, or within 24 hours, whichever comes first. Only the facts you approve persist as your record.
- The consent step is kept as a record. Because the law cares about agreement, the fact that consent was given — with its time and the disclosure used — is retained as a compliance record. That record is a deliberate exception to the transcript deletion above; our privacy notice lists it.
- Nothing joins the call before agreement. The assistant's audio path is gated by the server, not by an instruction inside the model, and the gate resets if the call is transferred or put on hold or if a new person joins.
- Provider-side retention is not yet zero. Our model provider's default configuration may retain call content in abuse-monitoring logs for up to 30 days. We have asked for written confirmation and zero-data-retention treatment and do not have that answer yet. We would rather state this plainly than imply a guarantee.
- Account protection. Access is by invitation, and sign-in uses phone verification with PIN recovery. We will not describe the details of that flow as verified here until it is live and tested with a real handset.
What we are not claiming
- We do not claim HIPAA compliance, and Withstead is not designed for health information. Do not use it for clinical or medical matters.
- We hold no security certification — no SOC 2 report, no ISO 27001 certificate — and we have not published a third-party penetration test. We will not imply otherwise on this page or elsewhere.
- We do not claim that any configuration makes a call legally compliant in your state. That depends on your call, your disclosure, and your law. See acceptable use.
- We do not offer a security guarantee, an uptime commitment, or a breach-response time commitment on this page. What we will do is tell you what we find.
Reporting a security problem
If you find a vulnerability in this site or in the product, write to [email protected] with enough detail to reproduce it. Please do not test against other people's accounts, do not access or alter data that is not yours, and give us a reasonable chance to fix the issue before you publish it. We will confirm receipt and tell you what we find.
Changes to this page
We will date any change, and we will keep stating limits rather than dropping them quietly. If a claim here becomes true or stops being true, this page is where that shows up.
This page is part of the Withstead notice set: Terms of service · Acceptable use · Security · Privacy · For the person on the other end of the call