Security
What this site does to stay safe to visit, and how to tell us if it does not.
This site holds nothing
www.msrx.co.in is a static site. It has no database, no accounts, no forms and no API. There is no session to hijack and no stored record of your visit to leak, because none is created.
Fonts are self-hosted rather than pulled from a font CDN, so loading a page here does not tell a third party that you did.
Response headers
- Content-Security-Policy
- Scripts, styles, fonts and images may only load from this origin. Framing, plugins and outbound connections are blocked outright.
- Strict-Transport-Security
- Two years, including subdomains, preload-eligible. Browsers refuse to reach this site over plain HTTP.
- X-Frame-Options / frame-ancestors
- Denied. The site cannot be embedded in a frame anywhere, which rules out clickjacking.
- X-Content-Type-Options
- nosniff. Browsers honour the declared content type instead of guessing at it.
- Referrer-Policy
- strict-origin-when-cross-origin. Outbound links carry the origin, never the full path.
- Permissions-Policy
- Camera, microphone, geolocation, payment and USB are all denied, as is FLoC cohort calculation.
The apps themselves
Each MSRX app runs on its own subdomain or ships through the App Store, and each states its own data handling. As a rule, the web apps process in your browser and the native apps process on your device.
See the privacy policy for what is and is not collected, and each app's own page for its specifics.
Reporting a vulnerability
If you find a security issue in this site or in any MSRX app, email it directly. Include what you found, how to reproduce it, and what you think the impact is. Reports are read by the person who wrote the code, and there is no triage queue in between.
mrinalsinghraja@gmail.com