Static-first and restrictive by default.
The public site is designed as a static deployment with minimal JavaScript, restrictive security headers, no embedded third-party advertising, and optional analytics loaded only after consent. Security controls are tested against required site functions before deployment.