ROYALFIRE

About

Lakshay

I build and operate hosting platforms. Not the marketing kind — the part where a customer opens a ticket at midnight and something has to actually work.

Most of what I have shipped I have also tried to break. I wrote an authorised black-box assessment of my own dashboard and found eight issues, one of them critical: a placeholder test account sitting in the production root-access list, one login away from full control. I did not enjoy finding it. I would have enjoyed not finding it, and then never knowing.

That is the whole point of that report and of putting it on a public site rather than quietly fixing it. A security claim you have not tested is a rumour.

How I work

  • Delete fails closed. If any check cannot be evaluated, nothing gets deleted.
  • Authorisation is enforced server-side. Hiding a button is not access control.
  • Write down the invariant, then make the code refuse to violate it.
  • Say what you would change. It makes everything else you claim believable.

About this site

Royalfire is a static site. No database, no server-side code, no cookies, no analytics, no third-party scripts, and no fonts loaded from anywhere but this domain. That is not minimalism for its own sake — it is the largest single security decision available, because there is no runtime here to patch or breach. It is open source and self-hosted font files for the same reason.

It is built with Astro and edited through a git-based admin panel, which means adding a project is a form rather than a deployment.