Legal
Security of Dhiti itself
A security vendor whose own site leaks to ad networks loses the room. Dhiti ships a strict, nonce-based CSP, HSTS, and minimal Permissions-Policy; no third-party scripts run except a self-hosted analytics endpoint.
Our SDLC includes SAST/SCA on every merge, dependency and container scanning, and a published CBOM of our own stack. Admin is behind auth, rate limiting and an optional IP allowlist.
