Pathway Finder: security and privacy

For IT, web and compliance teams reviewing the Pathway Finder from Doctor Pathways Australia. This page prints to PDF for approval processes.

What it does

It asks where the doctor qualified (unless your snippet pre-sets a country, which the reader can always change), then two short questions about their qualifications, and shows their likely registration pathway. Each answer is a plain form that reloads the frame from https://doctorpathways.com.au/embed/pathway-finder, with earlier answers carried in the frame’s own address, not stored anywhere. The result’s links open our free guide at doctorpathways.com.au in a new tab. The frame is plain HTML and CSS, fixed at 360 pixels high.

What it cannot do

  • Run code: the frame contains no JavaScript, and its content policy forbids scripts.
  • Read, change or redirect your page.
  • Set cookies or use browser storage.
  • Ask for the camera, microphone, location, clipboard, payment or any other browser permission.
  • Identify a reader. It keeps nothing that identifies anyone, so there is nothing for your consent banner.

The sandbox in the snippet

allow-formsLets the reader answer each question inside the frame.
allow-popupsLets the result open our guide in a new tab.
allow-popups-to-escape-sandboxMakes that new tab a normal page rather than a sandboxed one.

Deliberately not allowed:

  • allow-scripts: no code runs in the frame.
  • allow-same-origin: the frame has no storage and cannot read your page or its cookies.
  • allow-top-navigation: the frame cannot redirect your page.

Response headers

Sent with every load of /embed/pathway-finder:

Content-Typetext/html; charset=utf-8
Content-Security-Policydefault-src 'none'; style-src 'sha256-wSvGx65SoUSg/rj0fmaKtyUO5cZJASENXrB8wL8I9Hg='; img-src 'self' data:; form-action https://doctorpathways.com.au; base-uri 'none'
Permissions-Policyaccelerometer=(), autoplay=(), camera=(), clipboard-read=(), clipboard-write=(), display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(), screen-wake-lock=(), usb=(), xr-spatial-tracking=()
Cross-Origin-Resource-Policycross-origin
Referrer-Policyno-referrer
X-Content-Type-Optionsnosniff
X-Robots-Tagnoindex
Cache-Controlprivate, no-store

No Set-Cookie and no X-Frame-Options. There is no frame-ancestors rule, so any site may embed the frame, including platforms that wrap it in their own sandbox.

Allow-listing

If your platform only embeds approved domains (SharePoint HTML Field Security, Blackboard, some Moodle setups), allow one domain: doctorpathways.com.au.

Counting

We count how many times the frame loads on each site. For each load we store your site’s address (which the snippet sends as an origin only, never the full page path), the reader’s country from their network, and a one-way code that changes every day so one reader is not counted twice. We store no IP address, set no cookie and keep nothing that identifies a reader. We also count each result shown, by pathway and by site, as a total. The result’s links carry your site’s address, so we can see how many readers each site sends.

Accessibility

Built to WCAG 2.2 AA: native form controls, visible focus, a labelled question, a frame title, and a button that says it opens a new tab. It follows the reader’s light or dark setting unless you pick one, works from 280 pixels wide, and scrolls inside the frame rather than clipping when text is enlarged.

Stability

The address and the snippet never need changing. Questions and wording are updated on our side. If the snippet itself ever had to change, it would get a new address, and the current one would keep working.

Neutral content

The Pathway Finder is educational. It contains no advertising, sign-up, recruitment or anything for sale, and it gives general information, not advice. The rules behind it come from the Medical Board of Australia’s published pages.

Contact

Security questions or reports: [email protected].