Independent project · Owner-reviewed
Security
A small, static, privacy-minimizing surface with no account or CJI-processing capability.
01 / BOUNDARY
Public reference, not an operational system
The site has no accounts, application database, server-side search, submission form, CAD/RMS/MDT connection, or intended CJI workflow. Users must not enter personal information, CJI, plates, identifiers, case numbers, or narratives.
No CJIS compliance claim is made. Adding identity, stored history, telemetry, agency integrations, or sensitive-data processing requires a new security and legal architecture review.
02 / CONTROLS
Current controls
The release uses a restrictive Content Security Policy, HTTPS and HSTS, framing protection, a restrictive referrer policy, bounded inputs, text-only result rendering, no third-party runtime scripts, deterministic builds, dependency inventory, and reproducible checksums.
Hosting-provider request and security metadata remain inside the infrastructure trust boundary. No security certification, CJIS authorization, penetration-test claim, or government authorization is made.
03 / REPORTING
Report a vulnerability
Submit a minimal report through https://github.com/kirbyjosh28/offense-code-index/issues or follow the published security.txt instructions. Reports filed in the public tracker may be visible to others.
Do not include PII, CJI, credentials, case information, or unnecessary exploit data in an initial report. Do not test against other users, government systems, or data you do not own or have express authorization to test.
04 / STATUS
Evidence before claims
Threat modeling, header verification, hostile-input testing, dependency review, rollback guidance, and artifact checksums are part of the release evidence. Review was performed by the owner and automated checks, not by an independent security assessor.
Operated by the Independent Illinois Offense Code Reference project. Owner-reviewed August 10, 2026.