Skip to content
inkore
FoundationsCatalogProduct statePricing
FR
Discuss a project
FoundationsCatalogProduct statePricingCapabilitiesMethodologyDiscuss a project

Public site

Security

Last updated — 7 September 2026

This page describes the actual security posture of the public inkore.io website: what is in place, what does not exist, and what is not certified. It follows the same rule as the rest of the site: no unverifiable claim.

What this site is

inkore.io presents Inkore and its products. Cue sales remain closed until its offer and packages are validated. The prepared commerce journey uses Stripe for payment, an order database and private file storage. It offers no user account or automatic email recovery. The website conversation assistant runs in your browser. Hosting logs are described in the privacy policy.

Technical controls in place

  • Encryption in transit across the whole site (HTTPS), with HSTS: two-year duration, subdomains included, preload directive present (domain not yet on the preload list).
  • Content Security Policy: styles limited to the site’s origin and served without “unsafe-inline”; scripts limited to the site’s origin and to www.googletagmanager.com, which only serves Google Analytics after your consent — for scripts loaded from outside; inline scripts remain allowed, see the limit below.
  • The site cannot be displayed inside a third-party frame: X-Frame-Options DENY and frame-ancestors 'none'.
  • Hardened headers: X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy denying camera, microphone and geolocation.
  • Audience measurement only after explicit consent; declining keeps the site fully usable and remains reversible at any time.

The header controls above can be verified from your browser by inspecting the site’s response headers.

A known limit of this policy, which we do not present as a strength: inline scripts remain allowed (“unsafe-inline” on script-src). The static build framework injects inline scripts into every page that a header shared by all routes cannot enumerate; forbidding them would mean giving up static rendering. The restriction therefore only covers the origin of scripts loaded from outside.

What does not exist on this site

  • No Inkore user accounts. Card details are entered at Stripe, never in an Inkore form.
  • Commerce endpoints store orders and access-code hashes. Test and production environments are separate, and sales remain closed by default.
  • No audience-measurement cookie before you agree.

What is not certified

The publisher holds no security certification to date (ISO 27001, SOC 2, HDS or equivalent), and the site has not undergone an independent external security audit. We will only claim it once it is true and verifiable.

Products in preparation, including Inkore Cue, have their own security requirements, documented separately. This page covers the public website only.

Reporting a vulnerability

If you believe you have found a vulnerability on inkore.io, write to hello@inkore.io. We acknowledge every report, review it promptly and keep you informed of its resolution. Please allow us a reasonable delay before any public disclosure. There is no reward programme at this time.

inkore

Inkore’s public site. No account, Wallet or AI module is activated on this site.

CapabilitiesMethodologyAboutParis StudioContactPrivacyLegal noticeTerms of useWithdraw from the contract hereSecurityProgressInkore Cue
© 2026 INKORE60 rue François 1er, 75008 Paris, France · hello@inkore.io