82 terms
Security & Infrastructure GlossarySecurity & Infrastructure Terms A–Z
The concepts that keep a website and the application behind it secure, reachable and compliant: HTTPS and TLS, security headers, common vulnerabilities such as XSS and CSRF, authentication methods, DNS records, CDNs, firewalls and personal data under KVKK and the GDPR.
The definitions are defensive: they explain how a weakness arises and how it is prevented, never how to exploit it. The infrastructure entries describe, in plain language, the layers a request passes through from the domain name to the server.
Searches term names and alternate names; on category pages also the short definitions.
A
- A and AAAA RecordsAn A record is the DNS record that maps a domain or subdomain to an IPv4 address such as 203.0.113.10; an AAAA record does the same for an IPv6 address. Before a browser can connect to a site, it looks up these records and opens a connection to the address returned. They are the records you change when moving servers, switching hosting or putting a site behind a CDN.Professional · Security & Infrastructure
- Access TokenAn access token is a credential showing that a client may call a protected API with specific permissions for a limited time. In OAuth 2.0 it is issued by the authorization server and usually sent in an Authorization: Bearer header. Access tokens are kept short-lived to limit the damage if one is stolen; when one expires, a longer-lived refresh token lets the client obtain a new one without making the user sign in again.Professional · Software · Security & Infrastructure
- API KeyAn API key is a long random string that an application sends with its requests so an API can identify the calling project or account. The provider uses it to attribute usage, enforce quotas and decide which operations are allowed. A key usually represents an application rather than a person and often never expires on its own, so a leaked key is a serious risk: keep it secret, restrict it and rotate it regularly.Core · Software · Security & Infrastructure
- AuthenticationAuthentication is the process of verifying that a user, device or service really is who or what it claims to be before granting access to a system. It relies on evidence such as a password, a one-time code, a passkey or a biometric check. Authentication answers "who are you?"; deciding what that verified identity may do is the job of authorization.Core · Software · Security & Infrastructure
- AuthorizationAuthorization is the process of deciding what an authenticated user, application or service is allowed to do with a specific resource. It grants or denies access based on roles, permissions, ownership or contextual rules. Where authentication answers "who are you?", authorization answers "are you allowed to do this?" — and it always runs after identity has been established.Core · Software · Security & Infrastructure
B
- BackupA backup is a copy of databases, files and configuration stored independently of the live system, so data can be restored after deletion, hardware failure, ransomware or a bad update. A backup plan is judged by how much data loss it accepts (the recovery point objective, RPO), how quickly service can be restored (the recovery time objective, RTO), and whether restores are actually tested on a regular schedule.Core · Software · Security & Infrastructure
- Bot ProtectionBot protection is the set of techniques used to separate automated traffic from human visitors, blocking abusive bots (form spam, credential stuffing, scraping, inventory hoarding) while still admitting wanted bots such as search engine crawlers. It draws on IP reputation, request rate, behavioural analysis, browser checks and challenges such as CAPTCHA or Cloudflare Turnstile.Professional · Security & Infrastructure
- Brute-Force AttackA brute-force attack tries to discover a password, PIN or cryptographic key by systematically trying possible values until one works. The family includes automated guessing against a login form, replaying username and password pairs leaked from other sites (credential stuffing) and cracking stolen password hashes offline. The main defences are multi-factor authentication, rate limiting, and long, unique passwords stored with a slow hashing algorithm.Core · Security & Infrastructure
C
- CDN (Content Delivery Network)A CDN (Content Delivery Network) is a distributed network of servers that caches a website's content at edge locations around the world and serves each user from the nearest one. Requests reach the CDN first; if the edge cache holds a fresh copy, the response is returned without contacting the origin server. This cuts latency and origin load, and most CDNs also handle TLS termination, compression and DDoS protection.Core · Web Design · Performance & Analytics · Security & Infrastructure
- ClickjackingClickjacking is an attack in which a page is loaded inside an invisible or disguised iframe on another site, so that a user clicks a button on it without realising. The user thinks they are clicking something harmless while actually changing a setting or confirming an action on a site where they are logged in. The main defence is restricting framing with the CSP frame-ancestors directive and the X-Frame-Options header.Professional · Security & Infrastructure
- CloudflareCloudflare is a US-based company that operates a global network acting as a reverse proxy in front of websites and applications, providing services such as DNS, CDN caching, DDoS mitigation, a web application firewall (WAF), bot management and serverless compute (Workers). Once a domain's nameservers point to Cloudflare, traffic to proxied records passes through Cloudflare's network before reaching the origin server.Professional · Performance & Analytics · Security & Infrastructure
- CNAME RecordA CNAME (canonical name) record is a DNS record that points a name at another domain name instead of an IP address; the resolver continues the lookup at the target and returns its A/AAAA records. It is typically used to connect subdomains such as www or shop to a hosting, CDN or SaaS provider. By standard, a CNAME cannot coexist with other records on the same name, so it cannot sit at the zone apex.Professional · Security & Infrastructure
- Consent Mode (Google)Consent Mode is a Google mechanism that passes a visitor's consent choices about cookies and data use to Google tags such as Google Analytics, Google Ads and Floodlight, which then adjust whether they store cookies. Version 2 added the ad_user_data and ad_personalization signals to ad_storage and analytics_storage. Consent Mode does not collect consent itself; a cookie banner or consent management platform does that.Advanced · Performance & Analytics · Security & Infrastructure
- Content Security Policy (CSP)Content Security Policy (CSP) is an HTTP response header that tells the browser which sources a page may load scripts, styles, images and connections from, and which sites may embed it in a frame. The browser blocks anything the policy does not allow. It is mainly used as an additional layer of defence that makes injected scripts much harder to execute in cross-site scripting (XSS) attacks.Advanced · Security & Infrastructure
- Cookie ConsentCookie consent is the practice of informing visitors and obtaining their permission before a website uses non-essential cookies and similar tracking technologies, then recording and honouring that choice. It is usually implemented as a banner with a preferences panel, often through a consent management platform (CMP). Strictly necessary cookies, such as session or security cookies, can generally be exempt, while advertising and tracking cookies require consent.Core · Performance & Analytics · Security & Infrastructure
- CORS (Cross-Origin Resource Sharing)CORS (Cross-Origin Resource Sharing) is the mechanism by which a server uses HTTP headers to declare which other origins may read its responses through JavaScript running in a browser. It relaxes the browser's default same-origin policy in a controlled way. CORS is enforced by browsers, not servers, so it offers no protection against requests sent to the server directly.Professional · Software · Security & Infrastructure
- CSRF (Cross-Site Request Forgery)CSRF (Cross-Site Request Forgery) is an attack in which another website causes a user's browser to send a state-changing request to a site where that user is logged in, without the user's knowledge. Because the browser attaches cookies automatically, the server may treat the request as genuine. The main defences are the SameSite cookie attribute, anti-CSRF tokens and verifying where a request came from.Professional · Security & Infrastructure
D
- Dark PatternA dark pattern is a user interface pattern designed to push people into decisions that work against their own interests. Pre-ticked consent boxes, fees revealed only at the final checkout step, fake countdown timers, subscriptions that are deliberately hard to cancel and cookie banners that hide the reject option are typical examples. The practice is now often called deceptive design, and consumer protection and data protection regulators in several jurisdictions have taken it up.Professional · Web Design · Security & Infrastructure
- DDoS AttackA DDoS (distributed denial-of-service) attack tries to make a website, server or network unavailable to legitimate users by flooding it with traffic from many devices at once. The traffic usually comes from botnets of compromised computers and IoT devices. Attacks can target bandwidth, the resources of network protocols, or the application itself, and defences are designed around those same layers.Core · Security & Infrastructure
- DependencyA dependency is a library, framework or tool, usually written by someone else, that a software project needs in order to build or run. Dependencies are installed through a package manager such as npm, pip or Composer; a manifest file declares the acceptable version ranges and a lockfile records the exact versions actually installed. Every dependency saves development time but also brings update, licensing and security responsibilities into the project.Professional · Software · Security & Infrastructure
- DKIM (DomainKeys Identified Mail)DKIM (DomainKeys Identified Mail) is an email authentication method, defined in RFC 6376, in which the sending server signs selected headers and the body of a message with a private key, and receivers verify the signature using a public key published in DNS. A valid signature shows that the signing domain took responsibility for the message and that it was not altered in transit. It does not encrypt anything.Advanced · Security & Infrastructure
- DMARCDMARC is an email authentication standard that lets a domain owner tie SPF and DKIM results to the visible From address, state what receivers should do with mail that fails (none, quarantine or reject), and receive reports about mail sent in the domain's name. The policy is a TXT record at the _dmarc subdomain. First specified in RFC 7489, it is now defined by RFC 9989, published in May 2026.Advanced · Security & Infrastructure
- DNS (Domain Name System)DNS (Domain Name System) is the distributed, hierarchical database that translates human-readable domain names such as example.com into IP addresses and other records that computers use. Browsers query it before connecting to a website, mail servers before delivering a message, and answers are cached for the duration of their TTL. Websites, email and domain verifications all depend on correct DNS records.Core · Security & Infrastructure
- Domain NameA domain name is a unique, human-readable name registered in the DNS hierarchy that lets people reach a website or service without knowing its IP address. In example.co.uk, “uk” is the country-code top-level domain and “example” is the registered name. Domains are not bought outright: they are registered through a registrar for a fixed period and must be renewed before they expire.Core · SEO · Security & Infrastructure
E
- EncryptionEncryption is the process of transforming readable data, using an algorithm and a key, into a form that only someone holding the correct key can turn back into the original. When the same secret key encrypts and decrypts, it is symmetric encryption; when a public and private key pair is used, it is asymmetric. On the web it underpins protecting data both in transit and at rest.Core · Security & Infrastructure
- Environment VariableAn environment variable is a named value that the operating system passes to a running process, which the application reads instead of relying on constants written into its code. Settings that differ between deployments, such as a database URL, an API key, a mail server or the name of the current environment, are supplied this way. The same code then runs unchanged in development, staging and production, and secrets stay out of source code.Professional · Software · Security & Infrastructure
- Explicit ConsentExplicit consent is permission to process personal data that a person gives knowingly, for a specific purpose and of their own free will, through a clear affirmative act. Turkey's KVKK defines it as consent that is specific, informed and freely given; the GDPR requires a similar standard and explicit consent for sensitive data. It can be withdrawn at any time and is only one of several legal bases, not the default.Professional · Security & Infrastructure
F
- FirewallA firewall is hardware or software that allows or blocks network traffic entering or leaving a network or server according to predefined rules. Rules are usually written in terms of source and destination IP address, port and protocol. Its basic job is to make sure only the services that genuinely need to be reachable are exposed, with everything else closed by default.Core · Security & Infrastructure
- First-Party CookieA first-party cookie is a cookie that belongs to the site the user is visiting, the domain shown in the browser's address bar. It can be set by the server through the Set-Cookie response header or written by JavaScript running on that page. Sessions, carts and language preferences rely on first-party cookies, and so do many analytics tools. Being first-party does not by itself exempt a cookie from consent or keep its data on the site owner's side.Professional · Performance & Analytics · Security & Infrastructure
G
H
- Hash FunctionA hash function is a one-way function that maps data of any length to a fixed-length value called a digest. The same input always produces the same digest, while the smallest change to the input produces a completely different one. For cryptographic hash functions such as SHA-256, recovering the input from the digest or finding two inputs with the same digest is infeasible, which is why they are used for integrity checks and digital signatures.Professional · Software · Security & Infrastructure
- HMACHMAC (hash-based message authentication code) is a method for producing a short authentication tag by running a message and a secret key, known only to sender and receiver, through a hash function such as SHA-256. The receiver repeats the calculation and compares results; a match shows the message was not altered and was produced by someone holding the key. Webhook signatures, API request signing and JWT's HS256 algorithm all use HMAC.Advanced · Software · Security & Infrastructure
- HSTS (HTTP Strict Transport Security)HSTS (HTTP Strict Transport Security) is a mechanism by which a site uses the Strict-Transport-Security response header to tell browsers to connect to it only over HTTPS for a set period. During that time the browser rewrites http:// addresses to https:// before sending anything and refuses to let users click through certificate errors, closing the gap that attacks on the first plain-HTTP request rely on.Professional · Security & Infrastructure
- HTTP CookieAn HTTP cookie is a small name-value pair that a web server asks the browser to store using the Set-Cookie response header. The browser keeps it and sends it back in the Cookie header on later requests that match its scope. Cookies keep users signed in, remember carts and language choices, and support analytics; attributes such as Domain, Path, Expires, Max-Age and Secure control where a cookie is sent and how long it lives.Core · Web Design · Software · Security & Infrastructure
- HTTP HeaderAn HTTP header is a name-value line of metadata, written as “Name: value”, that comes before the body of an HTTP request or response. Request headers tell the server which host is wanted, what formats the client accepts and who is calling; response headers describe the content type, caching rules, cookies and security policies. Header names are case-insensitive, and the standard fields are defined in RFC 9110 and related specifications.Core · SEO · Software · Security & Infrastructure
- HttpOnly CookieAn HttpOnly cookie is a cookie that the server marks with the HttpOnly attribute in its Set-Cookie header, which tells the browser to hide it from JavaScript running on the page. It cannot be read through document.cookie, yet it is still sent with HTTP requests to its domain. On session cookies, it stops an XSS flaw from simply reading the session ID and sending it elsewhere.Professional · Security & Infrastructure
- HTTPSHTTPS (Hypertext Transfer Protocol Secure) is HTTP carried over a connection encrypted with TLS. It prevents third parties from reading or altering the data exchanged between browser and server, and the site's certificate lets the browser confirm it is talking to the genuine domain. Browsers now label plain HTTP pages as not secure, and Google prefers the HTTPS version of a page as canonical.Core · SEO · Security & Infrastructure
J
K
L
- Load BalancerA load balancer is a network component that spreads incoming traffic across several servers running the same service and automatically stops sending traffic to servers that fail health checks. Clients connect to a single address, and the load balancer decides which backend handles each connection or request. It can work at layer 4 (TCP/UDP connections) or layer 7 (HTTP requests, routed by their content), adding capacity and keeping one server's failure from becoming an outage.Professional · Software · Performance & Analytics · Security & Infrastructure
- LoggingLogging is the practice of recording events that occur while an application or server runs, each with a timestamp, a severity level and contextual details. Logs are used for debugging, investigating security incidents and keeping an audit trail. Good logs are structured so machines can parse them, and they never contain secrets such as passwords or tokens, or more personal data than the purpose requires.Core · Software · Security & Infrastructure
M
- MFA (Multi-Factor Authentication)MFA (multi-factor authentication) is verifying a user's identity with at least two different kinds of evidence: something they know (a password), something they have (a phone or security key) or something they are (a fingerprint or face). Using exactly two factors is called 2FA. Because a stolen password alone no longer opens the account, MFA is one of the most effective defences against account takeover.Core · Security & Infrastructure
- Mixed ContentMixed content occurs when a page loaded over HTTPS requests some of its resources, such as images, scripts, stylesheets or iframes, over unencrypted HTTP. Those resources can be read or altered in transit. Modern browsers automatically upgrade image, audio and video requests to HTTPS and block other types such as scripts and stylesheets, which can leave the page looking broken.Professional · SEO · Security & Infrastructure
- MX RecordAn MX (mail exchanger) record is a DNS record that tells sending servers which hosts accept email for a domain. Each MX record holds a preference value and a hostname; senders try the host with the lowest value first and fall back to the next if it is unreachable. MX only governs inbound mail; authenticating outbound mail is the job of SPF, DKIM and DMARC.Professional · Security & Infrastructure
N
- NginxNginx (pronounced “engine-x”) is an open-source web server originally written by Igor Sysoev that also works as a reverse proxy, load balancer, content cache and TCP/UDP proxy. Its event-driven architecture handles large numbers of concurrent connections with little memory, which is why it is widely used to serve static files, terminate HTTPS and sit in front of application servers.Professional · Software · Security & Infrastructure
- NonceA nonce (“number used once”) is a unique, usually random value generated for a single use in a cryptographic operation or protocol message. Nonces stop recorded messages from being accepted a second time (replay protection), keep encryptions under the same key distinct from one another, and, in Content Security Policy, allow only approved inline scripts to run.Advanced · Software · Security & Infrastructure
O
- OAuthOAuth (in practice, OAuth 2.0) is an authorization framework, defined in RFC 6749, that lets an application access resources on another service on a user's behalf without ever learning the user's password. Instead, the application receives a scoped, time-limited access token. OAuth on its own is not an authentication protocol; signing users in is added on top by OpenID Connect.Professional · Software · Security & Infrastructure
- Open RedirectAn open redirect is a vulnerability where a site redirects visitors to a destination taken from a URL parameter without validating it. Because the link starts with a trusted domain, users, email filters and search engines treat it as belonging to that site, while the visitor actually lands on a phishing or spam page. In login and OAuth flows, an open redirect can also help leak authorization codes or tokens.Advanced · SEO · Security & Infrastructure
- OpenID Connect (OIDC)OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0. Where OAuth grants an application access to resources on a user's behalf, OIDC also tells the application who the user is and how they authenticated, by issuing an ID token: a signed JWT addressed to the client. Most “Sign in with…” buttons and modern single sign-on run on OIDC, which is published by the OpenID Foundation.Advanced · Software · Security & Infrastructure
- OWASP Top 10The OWASP Top 10 is an awareness document from the non-profit OWASP community that ranks the ten most critical security risk categories for web applications. The current edition is the 2025 release, with broken access control in first place. Categories are chosen from security testing data contributed by organisations plus a practitioner survey. It is a starting point for prioritising work, not a certification or a testing standard.Professional · Security & Infrastructure
P
- Password HashingPassword hashing is the practice of storing user passwords not as plain text or reversible ciphertext, but as the output of a deliberately slow, one-way algorithm such as Argon2id, scrypt or bcrypt, combined with a unique random salt per password. At login, the submitted password is hashed the same way and compared with the stored value. The goal is to make guessing passwords from a leaked database as expensive as possible.Professional · Security & Infrastructure
- Payment GatewayA payment gateway is the service that securely captures card and similar payments on a website or app, routes them to banks and card networks, and reports the result back to the merchant. Card data collection, encrypted transmission, authorisation, voids and refunds happen in this layer, and the integration model chosen largely determines the merchant's security burden and PCI DSS scope.Core · Security & Infrastructure · CMS & E-commerce
- PCI DSSPCI DSS (Payment Card Industry Data Security Standard) is the security standard for any organisation that stores, processes or transmits cardholder data, or can affect its security. It is published by the PCI Security Standards Council, founded by the major card brands. It is not a law, but card networks and acquiring banks enforce it contractually on merchants and service providers. The current version is v4.0.1.Advanced · Security & Infrastructure · CMS & E-commerce
- Penetration TestingPenetration testing (pentesting) is an authorised exercise in which security specialists look for vulnerabilities in a system, web application or network using the techniques a real attacker would, within a scope agreed in writing beforehand. The goal is to find weaknesses, demonstrate whether and how they can be exploited, and report them with remediation advice. Unlike automated vulnerability scanning, it verifies findings by hand and chains them together.Professional · Security & Infrastructure
- Personal DataPersonal data is any information relating to an identified or identifiable natural person. Besides direct identifiers such as a name or national ID number, it includes email addresses, phone numbers, IP addresses, cookie IDs, location data and photos whenever they can single out a person, alone or combined with other information. Data about health, biometrics or religious beliefs forms special categories that are subject to stricter rules.Core · Security & Infrastructure
- Principle of Least PrivilegeThe principle of least privilege is a core security rule that every user, service or process should receive only the access rights it needs to do its job, and only for as long as it needs them. It limits the damage a compromised account or a buggy program can cause, and applies to every access decision, from database users and API keys to CMS roles and server processes.Professional · Security & Infrastructure
- Prompt InjectionPrompt injection is a security vulnerability in which instructions placed in the input a language model processes change the application's behavior in ways the developer did not intend. In a direct injection the instructions are in the user's own message; in an indirect injection they are hidden in content the model reads, such as a web page, an email or a document. OWASP ranks it first (LLM01) in its 2025 Top 10 for LLM applications.Professional · AI Visibility · Security & Infrastructure
R
- Rate LimitingRate limiting caps how many requests a client may make within a time window, for example 60 requests per minute per IP address. When the limit is exceeded, the server rejects further requests, usually with a 429 Too Many Requests status and a Retry-After header saying how long to wait. It protects services against brute-force attempts and abuse, and stops any single client from degrading the system for everyone else.Professional · Software · Security & Infrastructure
- Reverse ProxyA reverse proxy is a server that accepts requests from clients, forwards them to one or more application servers behind it and returns their responses to the client. Clients only ever talk to the proxy and never see the servers behind it. TLS termination, load balancing, caching, compression and security filtering usually happen at this layer; Nginx, HAProxy and Caddy are common examples.Professional · Software · Security & Infrastructure
S
- SameSite Cookie AttributeSameSite is a Set-Cookie attribute that controls whether a cookie is sent with requests initiated from another site. Strict sends it only on same-site requests, Lax also allows top-level navigations using safe methods, and None sends it everywhere but requires Secure. It is an important layer of defence against cross-site request forgery (CSRF), though not a complete defence on its own.Professional · Security & Infrastructure
- Secrets ManagementSecrets management is the practice of storing sensitive values such as passwords, API keys, database credentials, encryption keys and tokens securely, delivering them only to the systems that need them, rotating them regularly and auditing who accessed them. Its first rule is that secrets never appear in plain text in source code, Git repositories or log files.Advanced · Software · Security & Infrastructure
- Security HeadersSecurity headers are HTTP response headers that tell the browser how to handle a page more safely. Strict-Transport-Security forces HTTPS, Content-Security-Policy restricts which sources may load scripts and other resources, X-Content-Type-Options disables MIME type sniffing and X-Frame-Options stops the page from being framed. They reduce the impact of attacks such as XSS and clickjacking but do not replace secure application code.Professional · Security & Infrastructure
- Session (Web)A web session is the mechanism that ties a user's successive requests together on top of stateless HTTP. In the classic design the server generates an unguessable session ID when the user signs in, keeps the associated data on its side and hands the ID to the browser in a cookie, which the browser sends back with every later request. The alternative keeps the state in a signed token held by the client.Core · Software · Security & Infrastructure
- SPF (Sender Policy Framework)SPF (Sender Policy Framework) is an email authentication method, defined in RFC 7208, in which a domain publishes a DNS TXT record listing the servers allowed to send mail on its behalf. Receiving servers check the connecting IP against that list. SPF validates the envelope sender (MAIL FROM), not the visible From address, so it is meaningful mainly in combination with DKIM and DMARC.Professional · Security & Infrastructure
- SQL InjectionSQL injection is a vulnerability that arises when an application pastes user-supplied data directly into the text of an SQL query, letting that data change what the query means. It can lead to data leaks, modified or deleted records and bypassed authentication. The primary defence is using parameterized queries, also called prepared statements, which send values to the database separately from the query text.Professional · Security & Infrastructure
- SSL/TLS CertificateAn SSL/TLS certificate is a digital document that binds a domain name to a specific public key and is signed by a trusted certificate authority (CA). When setting up an HTTPS connection, the browser validates it to confirm it has reached the right server. Certificates are grouped by validation level into DV, OV and EV, and their maximum lifetimes are being shortened in stages by industry rules.Core · Security & Infrastructure
- SSRF (Server-Side Request Forgery)SSRF (Server-Side Request Forgery) is a vulnerability in which an application fetches a user-supplied URL without proper validation, letting an attacker turn the server into a proxy that sends requests on their behalf. Because the server sits inside the network, it can reach admin interfaces, databases or a cloud metadata service that are invisible from the internet, which can lead to data exposure and stolen credentials.Advanced · Security & Infrastructure
- SubdomainA subdomain is a label added to the left of a domain name and defined in DNS as its own host, like "blog" in blog.example.com. Browsers and search engines treat a subdomain as a separate host: robots.txt, cookie scope and URL-prefix properties in Search Console all work at host level. Compared with a subfolder, a subdomain is more independent technically but more fragmented to manage.Professional · SEO · Security & Infrastructure
T
- Third-Party CookieA third-party cookie is set not by the site the user is visiting but by another domain embedded in the page, such as an ad server, a social button, a video player or a chat widget. Because the same cookie can be read on many sites, it lets that third party link a user's browsing across sites for ad targeting and measurement. Safari and Firefox block or partition such cookies by default; Chrome leaves the choice to users.Professional · Performance & Analytics · Security & Infrastructure
- TLS (SSL)TLS (Transport Layer Security) is the cryptographic protocol that protects a connection between two applications against eavesdropping, tampering and forged messages. HTTPS, secure email transport and most API traffic run on top of it. The name SSL, still widely used, comes from TLS's predecessor, which is now considered insecure. The versions that should be enabled today are TLS 1.2 and TLS 1.3.Professional · Security & Infrastructure
- TXT RecordA TXT record is a DNS record that attaches arbitrary text to a domain name. Originally meant for human-readable notes, it now serves two main purposes: proving domain ownership to services such as Google Search Console, and publishing email authentication policies for SPF, DKIM and DMARC. Its contents are public to anyone who queries DNS, so it must never carry secrets.Professional · Security & Infrastructure
V
- VPS (Virtual Private Server)A VPS (Virtual Private Server) is a virtual machine created by partitioning a physical server with virtualisation software and rented to a customer with its own operating system, root access and allocated CPU, memory and disk. It offers far more control than shared hosting, but responsibility for operating-system updates, security hardening and backups moves to the customer along with that control.Core · Software · Security & Infrastructure
- VulnerabilityA vulnerability is a weakness in software, configuration or a process that, if exploited, can compromise the confidentiality, integrity or availability of a system. It can stem from a coding error, an insecure setting, a design flaw or an outdated dependency. Publicly disclosed vulnerabilities are catalogued with CVE identifiers, and their severity is commonly expressed as a CVSS score.Core · Security & Infrastructure
W
- WAF (Web Application Firewall)A WAF (web application firewall) is a security layer that inspects incoming HTTP requests to a web application, including their content, and allows, blocks or challenges them according to rules. Where a network firewall looks at IP addresses and ports, a WAF evaluates the URL, headers, cookies and request body. It is used to filter common attacks such as SQL injection and XSS, rein in abusive bots and buy time until vulnerabilities are patched.Professional · Security & Infrastructure
- Web HostingWeb hosting is the service of running a website's files, database and application code on servers that are permanently connected to the internet, so visitors can reach the site at any time. Hosting models such as shared hosting, VPS, managed hosting and cloud platforms differ in resource isolation, who manages the server, how easily they scale and what they cost. Much of a site's speed, uptime and security depends on this layer.Core · Security & Infrastructure · CMS & E-commerce
X
#
- 3D Secure3D Secure is a protocol that lets the bank that issued a card authenticate the cardholder during an online card payment. Its current form, EMV 3-D Secure (3DS2), shares transaction and device data with the issuer so low-risk payments can be approved without any extra step, while riskier ones trigger a challenge such as a one-time passcode or approval in the banking app.Professional · Security & Infrastructure · CMS & E-commerce
- 401 Unauthorized401 Unauthorized is the HTTP status code meaning a request was not applied because it lacks valid authentication credentials for the target resource. Despite the name, it is about authentication rather than authorization. The server must send a WWW-Authenticate header describing how to authenticate, and the client may retry with new or corrected credentials.Professional · Software · Security & Infrastructure
- 403 Forbidden403 Forbidden is the HTTP status code meaning the server understood the request but refuses to fulfil it. If credentials were sent, the server considers them insufficient, so repeating the request with the same credentials will not help. The refusal can also have nothing to do with identity, coming instead from file permissions, IP restrictions, firewall rules or bot protection.Professional · SEO · Software · Security & Infrastructure
- 429 Too Many Requests429 Too Many Requests is the HTTP status code saying a client has sent too many requests in a given amount of time, in other words that it hit a rate limit. Defined in RFC 6585, the response may include a Retry-After header stating how long to wait. Google's crawlers treat a 429 as a sign that the server is overloaded, count it as a server error and slow down crawling.Professional · SEO · Software · Security & Infrastructure
- 502 Bad Gateway502 Bad Gateway is the HTTP status code a server returns when, acting as a gateway or proxy, it receives an invalid response from the upstream server it contacted to fulfil the request. The error is usually generated by an intermediary such as Nginx, a CDN or a load balancer, while the real fault typically lies with an application server that is down, restarting or listening on the wrong address.Professional · Software · Security & Infrastructure
- 504 Gateway Timeout504 Gateway Timeout is the HTTP status code a server returns when, acting as a gateway or proxy, it does not receive a timely response from the upstream server it needs to complete the request. The connection may well have been established; the problem is that no answer arrived before the proxy's timeout expired. Slow database queries, long-running work and waits on external services are the usual causes.Professional · Software · Security & Infrastructure
Other categories
- SEO Glossary167 termsCanonical URL · Core Web Vitals · Crawling · Entity
- GEO Glossary63 termsAI Visibility · Entity · GEO · Structured Data
- AI Visibility Glossary45 termsAI Visibility · Entity · GEO · LLM
- Web Design Glossary97 termsCore Web Vitals · Responsive Design · Web Accessibility · Above the Fold
- Software Glossary138 termsAPI · LLM · API Endpoint · API Key
- Performance & Analytics Glossary71 termsCore Web Vitals · Abandoned Cart · Bounce Rate · Call to Action
- CMS & E-commerce Glossary27 termsAbandoned Cart · Checkout · CMS · CRM

