RQM Technologies LLC - Security Policy Scope - https://www.rqmtechnologies.com - Vercel-hosted Vite/React storefront - POST /api/chat and POST /api/chat/end-session when enabled - The legacy Express server is not the canonical production runtime. Implemented Public Controls - HTTPS/TLS and HSTS with subdomains - Enforced Content Security Policy with same-origin executable content - Frame denial, MIME-sniffing prevention, restrictive referrer and permissions policies - Strict chat byte, field, content-type, method, path, history, session, and origin limits - Fail-closed chat configuration with a durable Vercel WAF prerequisite - Automated production dependency, passive web, and TLS checks Assessment Status Controls are mapped to Application Security and Development STIG V6R4 and Web Server SRG V4R5. This does not constitute DISA certification, authorization, approval, or an Authority to Operate. Hosting-platform controls and durable audit retention remain inherited or open unless supported by authoritative evidence. Responsible Disclosure Report suspected vulnerabilities, exposed secrets, or public-content security concerns to security@rqmtechnologies.com. Include the affected URL, reproduction steps, impact, and relevant request identifiers. Do not perform denial-of-service testing or submit sensitive data. Last updated: 2026-08-07