// Cache Valley Systems
Security Practices
This page describes the known security posture of the public website and how security is approached for proposed work.
Last updated: August 20, 2026
Website and contact form
The production website applies request-size limits, server-side input validation, database-backed rate limiting, same-origin API behavior, security headers, trusted-proxy handling, and generic error responses. A valid inquiry is stored before an email notification is attempted so notification failure does not discard the submission.
Operational logging is designed to avoid contact-form contents and credentials. No public website can eliminate all risk, and this description is not a certification or compliance guarantee.
Client systems
Security requirements for client work depend on the data, users, integrations, infrastructure, contracts, and applicable obligations. Those requirements, including access control, audit evidence, retention, recovery, testing, and incident responsibilities, must be defined for each engagement rather than inferred from this website.
Responsible disclosure
If you believe you found a security issue affecting this website, email contact@cachevalleysystems.com with a concise description and reproduction steps. Do not include secrets, regulated records, or data belonging to another person, and do not disrupt the service or access information beyond what is necessary to describe the issue.
We will review good-faith reports and coordinate next steps when the report is reproducible and within our control. This page does not authorize destructive testing or activity that violates law or third-party terms.