The site you're looking at right now. Deliberately minimal: no database, no CMS, no login to secure, just Express, Pug templates, and static files.
Research writeups, blog posts, and this projects list are all written as Markdown with frontmatter, checked into git, and compiled into static content at deploy time by a small Node build script. The live server never parses Markdown, it just serves pre-rendered, pre-sanitized HTML through the normal page layout. The front page pulls the most recent entries from all three collections automatically, so new writeups and posts show up there without touching a template. The same build step also generates an RSS feed and a sitemap, so neither has to be maintained by hand.
It's hardened the way I'd want a security company's own site to be: a tuned Content Security Policy and the rest of the standard security header set, SPF, DMARC, DNSSEC, and CAA all set on the domain, and SSH locked down to key-only auth with modern algorithms only. Full details, including what it looked like before the fixes, are in the security audit writeup.
Deploys go through a GitHub Action that runs a real test suite first, covering every route, the security headers, and the phish-report flow end to end, before anything reaches the server. Dependency updates arrive as Dependabot pull requests instead of ad hoc npm audit fix runs, and an uptime monitor pings a dedicated health check endpoint so I find out about problems before a visitor does.