Skip to main content
Kynn Technologies

Security

This page describes the Kynn Technologies website’s security boundaries and the local-first design intent for MaxTTS Reader.

The website and the reader have separate responsibilities. Information here about the website is not an assurance about a released version of the app.

Last reviewed:

Website data boundaries

The website does not collect documents, filenames, reading activity, notes, exam content or other document-derived data from MaxTTS Reader.

Enquiries are separate from document work. Share only the information needed for your question; do not send customer documents or private records through a website form or email.

Local-first design

MaxTTS Reader is in development with a local-first design: reading and document processing are intended to stay on your device.

Licensing, updates and other network-dependent services have separate responsibilities. These design boundaries do not establish an audit or security certification of the app.

Network and service boundaries

Loading this website connects your browser to the hosting service. The site also requests its typeface from Google Fonts. Those requests involve ordinary connection information, such as your IP address and browser information.

The website’s configured referrer policy omits the page URL from outgoing referrer information. A system-font fallback keeps text available if the remote font does not load.

The theme choice is saved in your browser’s localStorage. It is not stored in a theme-preference cookie.

Website safeguards

The website’s configured Content Security Policy restricts the origins from which its resources can load. Response headers prohibit embedding the site in another page and disable unused browser capabilities such as camera, microphone and location access.

Build and browser checks examine these settings. They do not replace operational review or establish independent security certification.

Report a security concern

Email security@kynntechnologies.com with a description of the concern and enough information to identify the affected page or behavior.

Do not include passwords, private keys, customer documents or sensitive personal information in the initial message. The security.txt file lists the reporting address and its expiry date.