Security

What this site does to stay safe to visit, and how to tell us if it does not.

This site holds nothing

www.msrx.co.in is a static site. It has no database, no accounts, no forms and no API. There is no session to hijack and no stored record of your visit to leak, because none is created.

Fonts are self-hosted rather than pulled from a font CDN, so loading a page here does not tell a third party that you did.

Response headers

Content-Security-Policy
Scripts, styles, fonts and images may only load from this origin. Framing, plugins and outbound connections are blocked outright.
Strict-Transport-Security
Two years, including subdomains, preload-eligible. Browsers refuse to reach this site over plain HTTP.
X-Frame-Options / frame-ancestors
Denied. The site cannot be embedded in a frame anywhere, which rules out clickjacking.
X-Content-Type-Options
nosniff. Browsers honour the declared content type instead of guessing at it.
Referrer-Policy
strict-origin-when-cross-origin. Outbound links carry the origin, never the full path.
Permissions-Policy
Camera, microphone, geolocation, payment and USB are all denied, as is FLoC cohort calculation.

The apps themselves

Each MSRX app runs on its own subdomain or ships through the App Store, and each states its own data handling. As a rule, the web apps process in your browser and the native apps process on your device.

See the privacy policy for what is and is not collected, and each app's own page for its specifics.

Reporting a vulnerability

If you find a security issue in this site or in any MSRX app, email it directly. Include what you found, how to reproduce it, and what you think the impact is. Reports are read by the person who wrote the code, and there is no triage queue in between.

mrinalsinghraja@gmail.com