Website Security
Last updated: August 27, 2026
This page covers the public website at nibblemaps.com. It is not a claim that the iOS app, iCloud/CloudKit, Firebase Authentication, Apple services, or internal development systems have completed an independent security audit.
A live header check on August 27, 2026 confirmed that nibblemaps.com and /security return browser security headers including CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Current Website Controls
- Content Security Policy limits scripts, styles, fonts, images, and connections to approved sources.
- HTTP Strict Transport Security instructs browsers to use HTTPS for the site and subdomains.
- Frame and MIME-sniffing protections reduce common browser attack paths.
- Referrer and browser permissions policies limit unnecessary browser data and feature access.
What Was Checked
- Live response headers for the homepage and the Security page.
- The existing historical SecurityHeaders / Probely scorecard image.
- The public link for an independent, current SecurityHeaders scan.
App and Cloud Services
NibbleMaps uses platform services including Apple iCloud/CloudKit, Sign in with Apple, StoreKit, MapKit, device permissions, and Firebase Authentication for email-link sign-in. Security for those services is shared with the platform providers and depends on user account, device, and network settings.
Independent Verification
External report: SecurityHeaders / Probely scan results .
Report a Security Issue
Please send security concerns to nibblemaps@gmail.com.