# security/

tokens, xss, and content security policy. the browser is not a place where you can keep a secret, and most of frontend security is accepting that.

- [token-storage](/knowledge/frontend/security/token-storage/)
