Official Source: This Website

This domain is very legit.

You are currently connected to VeryLegit.site over HTTPS. The certificate exists, DNS returned something, and we have not personally observed this page doing a virus.

HTTPS has the little lock thing DNS returned an IP address This sentence says it is safe
Expensive-Looking Legitimacy Orb
THINKING GREEN THOUGHTS
Certificate Situation HAS ONE
DNS Event CAME BACK
Malware We Personally Saw WE DIDN'T SEE ANY
Risk Ownership FUTURE US'S PROBLEM
Evidence Entered Into Evidence

Reasons we have cleared ourselves.

We investigated ourselves using criteria that were available nearby. The results are shown below in large type, which makes them easier to trust.

Website Has Certificate
YES
Criminal websites famously cannot obtain these.
Critical CVEs We Are Counting
0*
*Known to the part of the dashboard currently rendering zero.
Open Source Reviewers
14,382
Estimated from package count. Every dependency is basically another auditor.
Uptime Since You Got Here
100%
Measured continuously since you opened this tab.
Independent Internal Review

Verify us with software we wrote.

Our verification engine checks the facts most likely to confirm our existing conclusion. Historically, this has produced excellent results.

verylegit-audit.service
curl https://verylegit.site --insecure
Website returned HTML. Strong opening.
openssl s_client -connect verylegit.site:443
Certificate contains certificate-like properties.
sha256sum artifact.bin artifact.bin
Hash matches itself exactly.
dig verylegit.site
Received an IP address. Case nearly closed.
Unexpected Career Development

The network is now your problem.

Survive until the incident timer expires. Use the available enterprise defenses, all of which were selected because they fit on buttons.

ACTIVE INCIDENT: CONFIGURATION HAS MET THE INTERNET Objective: keep production above 0% until the auditor loses interest.
SEV-1-ish
DATACENTER: closet-rack-final
WAVE: networking happening
Controls With Security Words In Them

Several settings are definitely configured.

The following controls were located in production or in a diagram that strongly implied production. Green labels have been added where appropriate.

PADLOCK VISIBLE
TLS
The Little Lock Thing
Traffic is encrypted between you and whatever eventually happens to it.
BETTER THAN BEFORE
IAM
Password Is Not Password
Production password confirmed to be neither "password" nor "password1".
MOVED
SEC
Secret Relocation Program
Credentials removed from README.md and placed somewhere people are less likely to read.
MAXIMUM COMPATIBILITY
FW
Allow From Anywhere, But Securely
0.0.0.0/0 allows customers to connect from an impressive variety of locations.
VERY OBSERVABLE
LOG
Evidence Accumulation
Every event is logged until disk space becomes a cross-functional discussion.
DO NOT EDIT
ENV
Please Don't Touch .env
.env renamed to .env-final-DO-NOT-EDIT-v3 to prevent accidental changes.
SEPARATE NAMES
DB
Different Hostnames
Staging and production have different hostnames, establishing a visually distinct boundary.
AFTER DEPLOY
CI
Eventually Secret Scanning
Secret scanning runs automatically shortly after the secret would have mattered.
ZERO-ISH TRUST
ZT
Zero Trust, With Exceptions
We trust nothing by default except existing production systems and users who already have access.
A Diagram Has Been Prepared

Several boxes are involved.

Requests travel through the following architecture before reaching the service Dave wrote in 2019. Nobody has touched it because that would technically make them the owner.

THE INTERNET contains strangers, bots, and several smart refrigerators
SECURITY-SHAPED BOX checks headers, vibes, and whether the request looks expensive
DAVE'S SERVICE runs as root for historical reasons nobody can reproduce
Architecture reviewed by everyone still willing to be mentioned near the architecture.
Things We Have Decided Could Happen
Potential Visitor Someone with developer tools open
Attack Surface The parts connected to the internet, plus one printer
Main Defense A convincing amount of green UI
Supply Chain npm install completed without immediately failing
Blast Radius Believed to remain within the blast radius
Incident Plan Create #incident-war-room-final-2 if #incident-war-room is busy
Residual Risk Accepted on behalf of future us