Security &
Disclosure
SIGIL Labs operates under a policy of full transparency regarding visitor data practices, site security posture, and data handling. This page is provided for institutional evaluators, security reviewers, and any visitor who wants to understand exactly what this site does and does not do with their information.
This site collects browser fingerprints
When you visit this site, a passive fingerprinting script collects approximately 40 browser and device signals — including screen resolution, timezone, CPU core count, device memory, installed language, and other hardware/software characteristics. This data is combined into a hash and logged server-side along with your IP address and the page you visited.
SIGIL Labs operates in the defense, aerospace, and government research space. Understanding who is evaluating the lab — what organizations, what device profiles, what geographic regions — is a legitimate operational security interest. This data is used exclusively for internal vetting and security awareness. It is never sold, licensed, or shared with any third party.
- —Sell or license visitor data to any party
- —Share data with advertising networks
- —Use data for behavioral targeting
- —Attempt to de-anonymize individual visitors
- —Retain data beyond operational necessity
- —Combine fingerprint data with external data brokers
Fingerprinting can be partially or fully evaded using Tor Browser, Brave with resistFingerprinting enabled, or NoScript. This is acknowledged and accepted. Visitors using managed corporate or government devices — the primary audience for this site — will generally be captured accurately. Visitors who require anonymity and have the technical means to achieve it are welcome to use those tools.
What is collected, stored, and retained
| Data Type | Collected | Stored | Shared | Purpose |
|---|---|---|---|---|
| Browser fingerprint hash | Yes | Yes | No | Visitor identification |
| IP address | Yes | Yes | No | Geographic/org context |
| Page visited | Yes | Yes | No | Access pattern logging |
| Screen resolution | Yes | Yes | No | Device profiling |
| Timezone | Yes | Yes | No | Geographic context |
| CPU core count | Yes | Yes | No | Device profiling |
| Device memory | Yes | Yes | No | Device profiling |
| Contact form submissions | Yes | Yes | No | Partnership processing |
| Cookies (advertising) | No | No | No | N/A |
| Third-party analytics | No | No | No | N/A |
| Payment information | No | No | No | N/A |
Infrastructure & operational security
- —Served over HTTPS with TLS encryption in transit
- —No shared hosting — dedicated containerized deployment
- —No third-party CDN with data retention agreements
- —Server-side rendering — no client-side data exposure
- —Fingerprint data stored in isolated MySQL database
- —Database access restricted to application layer only
- —Report endpoint protected by secret token authentication
- —No external database replication or backup services
- —Honeypot field active — bot submissions silently rejected
- —Server-side input validation and sanitization on all fields
- —Form submissions routed to operator-controlled inbox only
- —No third-party form processing services
- —Fingerprinting evadable via Tor / Brave resistFingerprinting
- —Server-side logging does not capture JS-disabled crawlers
- —No WAF or DDoS mitigation beyond hosting provider defaults
- —Static SAST findings present — reviewed, assessed as non-exploitable
Questions about this disclosure
Institutional evaluators, security reviewers, or legal teams with questions about SIGIL Labs' data practices, site security posture, or this disclosure are welcome to submit a formal inquiry. Responses are provided to verified organizational contacts.
This disclosure was last reviewed: August 2026. It reflects the current production deployment of sethbrumenschenkel.com.
Submit Security Inquiry