Check this site yourself
We would rather show than tell. Open your browser's developer tools on any page of this site and confirm:
- It sets no cookies and makes no third-party requests. Every request goes to carnival12.com.
- It loads no analytics, no tracking pixels and no third-party fonts or scripts.
- Its fonts, styles and scripts are served from this domain only.
The footer says the same thing, and our tests fail the build if it ever stops being true.
Security headers
Every response carries a strict set of security headers:
- Content-Security-Policy with no
unsafe-inline: scripts and styles run only from this origin. - Strict-Transport-Security: HTTPS is enforced.
- X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, and frame-ancestors none (the page cannot be framed).
We also turned off the edge network's error-reporting headers, so no browser reports leave for a third party.
Where this site runs
The site is static. It is served through Cloudflare, then Amazon CloudFront, from a private Amazon S3 bucket in Carnival 12 Ai's own AWS account (US East). The bucket is not public; only the CDN can read it.
What this website collects
Today, this marketing website collects nothing about you: no cookies, no identifiers, no analytics, no third-party requests. Standard server logs record that a page was served, without profiling you.
When we add a contact form that stores your message and, later, first-party visit counts, both will live in Carnival 12 Ai's own AWS account, never a third-party vendor, and both will honour Global Privacy Control and Do Not Track. This page and the privacy policy will say exactly what is collected before that goes live.
How we handle client data
Client data is never shared or sold, to anyone, ever. The systems we build for clients run where the client decides — on their hardware, in their private cloud, or in an environment we manage for them alone. Your data is not used to train shared models, every AI action is logged, and a person approves anything that commits money or moves equipment.
The full commitments are on the home page under Data sovereignty.
How we prove it
Every release is proven on a staging copy before it reaches this domain, and again on the live site: a test suite checks that there are no third-party requests, no cookies, no console errors, and that the security headers are exactly as described. The evidence is kept with each release.
Report a security issue
If you believe you have found a security vulnerability on this site or in one of our systems, please report it privately to security@carnival12.com. Tell us what you found and how to reproduce it. Please do not access or change data that is not yours, and please give us a reasonable opportunity to resolve the issue before any public disclosure.
We will acknowledge valid reports, keep you informed as we investigate, and work with you in good faith to resolve the issue.
If you make a good-faith effort to follow this policy during your research, we will treat your research as authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and fix the issue quickly. This does not permit you to access data beyond what is necessary to demonstrate the issue, to disrupt our services or those of our clients, or to violate the law.