SSL/TLS Operational

Security & Encryption

Transparent documentation of our transport layer security, certificate management, and data protection standards.

// Connection Status

🔒 Protocol

TLS 1.3

Latest transport layer security protocol enforced across all endpoints.

📜 Certificate

Valid

EV SSL issued by Let's Encrypt / DigiCert. Auto-renewal active.

🛡️ Perfect Forward Secrecy

Enabled

Ephemeral key exchange (ECDHE) ensures past sessions remain secure.

⚡ HSTS

Strict

Forces HTTPS for 1 year, including subdomains. Preloaded in browsers.

// Certificate Details

FieldValue
Subject Alternative Names*.1990webarchive.com, 1990webarchive.com, api.1990webarchive.com
IssuerDigiCert Global Root G2
Key AlgorithmRSA 4096-bit / ECDSA P-384
Signature AlgorithmSHA-256 with RSA
Valid From2025-01-15 00:00:00 UTC
Valid Until2026-02-12 23:59:59 UTC
SHA-256 FingerprintA3:4F:9C:11:E8:7D:22:B9:04:F5:8A:12:C3:99:D0:4E:77:81:F4:33:A2:10:55:CC:66:E9:11:88:44:09:AA:22

// Security Headers

HTTP Response Security Policy

// Privacy & Data Handling

🔐 End-to-End Encryption

All API requests and archive downloads are encrypted in transit. Sensitive researcher credentials are hashed using bcrypt.

📦 Minimal Logging

We log only anonymized IP ranges and request timestamps for rate-limiting. No personal data is stored beyond 30 days.

🌍 Data Residency

Archival data is distributed across geographically redundant nodes. User metadata complies with GDPR & CCPA standards.

Found a Vulnerability?

We take security seriously. Please report issues privately. We follow responsible disclosure guidelines and reward valid findings.

Report Vulnerability /.well-known/security.txt | PGP Key: 8F3A 4B2C 9D11 E5F0