Platform Security & Architecture
How Dart Host isolates, encrypts, and protects static HTML deployments worldwide
1. Zero Malware Sandbox
All uploaded HTML projects are stored in strictly isolated directory paths per user ID. Server-side script execution engines (like PHP, CGI, Python, or shell binaries) are completely disabled inside user upload storage through multi-layered server policies and `.htaccess` controls.
2. Automated SSL & Encryption
Every HTML project deployed receives automated SSL certificates supporting modern cipher suites and TLS 1.3 protocol. HTTP Port 80 inbound requests are automatically upgraded via 301 permanent redirect to encrypted Port 443.
3. Prepared PDO Statements
All database operations throughout Dart Host use PHP PDO with parameterized queries and strict type binding. This architectural guarantee eliminates SQL injection vulnerabilities across registration, project publishing, and administration.
4. CSRF & Session Isolation
All mutating POST actions (uploads, code edits, account settings, deletions) require cryptographically randomized CSRF tokens. User sessions are regenerated on authentication to prevent session fixation and hijacking attacks.
Responsible Vulnerability Disclosure
Security researchers who discover potential vulnerabilities in our hosting engine are encouraged to disclose them responsibly to our security team before public disclosure.