Security & network access
branchhelm.com. There are no advertising, analytics, or social tracking pixels. Corporate network access
Allow the smallest set needed for your use case:
https://branchhelm.com— required for the website and presentation media.https://challenges.cloudflare.com— optional; used only when a visitor reaches a protected waitlist or feedback form.https://branchhelm.com— installer metadata and bytes use the same first-party origin; website visitors do not need direct GitHub access.
If the CAPTCHA host is blocked, the presentation remains readable and its media stays first-party; only protected form submission is unavailable. BranchHelm does not use alternate domains to evade an organisation’s filtering policy.
Website controls
- HTTPS-only canonical origin with HSTS and automatic certificate renewal.
- Content Security Policy, clickjacking protection, MIME sniffing protection, and strict cross-origin resource policies.
- Exact deployment allowlist: undeclared files, source maps, symlinks, secrets, and local paths fail the production build.
- Server-validated CAPTCHA, exact origin checks, request-size limits, time traps, and rate limiting on public forms.
- No website account, advertising profile, or analytics identifier.
Desktop application boundary
BranchHelm is local-first. Repository contents, agent activity, credentials, and Git operations stay on the user’s machine. Optional update checks and user-initiated remote operations contact their stated providers. See the Privacy Policy for the complete boundary.
Report a security concern
Email a suspected vulnerability directly to support@branchhelm.com. This route does not depend on the website CAPTCHA. You can also use the protected feedback form and select “Bug report”. Include the affected URL or version, impact, reproduction steps, and a safe way to reply. Do not include credentials, private source code, or active exploit payloads in the first message.
Automated disclosure tooling can discover the canonical security.txt record.