Revise

Revise

View product →
amitfeldmanhq
amitfeldmanhq

@amitfeldmanhq

A free AI editor for Word files — docs are personal, so trust signals matter more here than for most launches.

Passive check on revise.io today (headers + public config only):

The good: ~90 ms responses, TLS 1.3, robots and sitemap live — and you've clearly been hardening: a real Content-Security-Policy exists, with a report endpoint wired up.

One finding: that CSP is still report-only. Content-Security-Policy-Report-Only logs violations but blocks nothing; renaming the header to Content-Security-Policy flips the exact policy you already wrote to enforcing. While you're in there: HSTS, X-Content-Type-Options, Referrer-Policy and Permissions-Policy are all still unset. You terminate on CloudFront, so a managed response-headers policy attaches all four in one rule — no app code touched.

For a product people upload their documents to, an enforcing CSP + HSTS is the visible "we thought about it." Happy to re-run the check free once it flips. Good luck with launch week!

August 17, 20260 likes 0 replies
Share: