Infrastructure & Threat Defense

Platform Security & Architecture

How Dart Host isolates, encrypts, and protects static HTML deployments worldwide

TLS 1.3 Strict
Automated HTTPS handshakes
Sandboxed Files
Isolated per-user directory trees
Port Filtering
Strict HTTP/HTTPS/DoT Ports

1. Zero Malware Sandbox

All uploaded HTML projects are stored in strictly isolated directory paths per user ID. Server-side script execution engines (like PHP, CGI, Python, or shell binaries) are completely disabled inside user upload storage through multi-layered server policies and `.htaccess` controls.

Prevents RCE and unauthorized server escalation

2. Automated SSL & Encryption

Every HTML project deployed receives automated SSL certificates supporting modern cipher suites and TLS 1.3 protocol. HTTP Port 80 inbound requests are automatically upgraded via 301 permanent redirect to encrypted Port 443.

HSTS and zero plaintext transmission

3. Prepared PDO Statements

All database operations throughout Dart Host use PHP PDO with parameterized queries and strict type binding. This architectural guarantee eliminates SQL injection vulnerabilities across registration, project publishing, and administration.

Zero raw concatenations in queries

4. CSRF & Session Isolation

All mutating POST actions (uploads, code edits, account settings, deletions) require cryptographically randomized CSRF tokens. User sessions are regenerated on authentication to prevent session fixation and hijacking attacks.

Strict token validation on all forms

Responsible Vulnerability Disclosure

Security researchers who discover potential vulnerabilities in our hosting engine are encouraged to disclose them responsibly to our security team before public disclosure.

Report Security Issue