Security-Conscious Publishing
This page explains how sudoRunner is designed as a public cybersecurity portfolio while limiting unnecessary exposure of personal, academic, client, or sensitive information.
Principle: This site is meant to show proof of work, technical depth, and professional thinking without publishing raw submissions, private identifiers, confidential data, or unnecessary sensitive details.
Privacy-Conscious Public Resume#
The public resume available on this site is intentionally privacy-reduced for open web publishing.
It uses:
Vlad K.as the public display name- a professional contact alias
- broad location only
- no private phone number
- no private personal email address
Professional Contact Alias#
This site uses:
as the public-facing contact email.
The address is configured as a professional forwarding alias through Cloudflare Email Routing. This allows professional contacts to reach me without requiring my private inbox address to be posted directly on the website.
Redacted Project Publishing#
Projects and labs are rewritten into sanitized case studies.
Raw academic files, full solution files, sensitive screenshots, lab credentials, private identifiers, and unnecessary procedural details are not published.
Before publishing project content, I review for:
- full names of classmates, professors, or unrelated individuals
- private email addresses
- phone numbers
- student IDs
- raw screenshots with identifying details
- credentials, secrets, tokens, or keys
- lab-specific IP addresses when not needed
- full exploit instructions or unnecessary offensive detail
- client names or proprietary implementation details
- anything that could violate academic, employer, or client confidentiality
Security Contact Standard#
Site Metadata Files#
This site includes standard public metadata files:
These files support search engine discovery, basic site transparency, and standard security contact discovery.
This site includes a public security.txt file at:
This provides a standard location for security contact and policy information related to the site.
Security Headers#
This site includes basic security headers through Cloudflare Pages static header configuration.
Configured headers include:
X-Frame-OptionsX-Content-Type-OptionsReferrer-PolicyPermissions-PolicyCross-Origin-Opener-Policy
These headers help reduce common browser-side risks such as clickjacking, unnecessary permission exposure, MIME sniffing, and excessive referrer leakage.
Static Site Deployment#
sudoRunner is deployed as a static website using Hugo, GitHub, and Cloudflare Pages.
This approach has several security and maintenance advantages:
- no traditional database exposed to the public
- no WordPress-style admin panel
- no server-side login portal
- version-controlled content changes
- automated deployment through Git
- simple rollback through repository history
- fast static hosting through Cloudflare
Content Boundaries#
This website does not publish:
- client data
- private employer documents
- internal implementation screenshots
- raw academic submissions
- private contact details
- credentials or secrets
- full exploit walkthroughs
- sensitive infrastructure details
The goal is to demonstrate cybersecurity knowledge, project experience, and technical communication while respecting privacy, confidentiality, and professional boundaries.