Pixeltable · Vulnerability Disclosure
Pixeltable Vulnerability Disclosure
Vulnerability disclosure
Pixeltable runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
CompanyAi DataMultimodal AIAI Data InfrastructureVector SearchEmbeddingsRAGAgent MemoryMCPOpen-SourcePythonData OrchestrationComputed ColumnsVideo ProcessingMachine-Learning
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
security@pixeltable.com
Source
Vulnerability Disclosure
generated: '2026-08-17'
method: searched
probe: true
source: https://pixeltable.com/security
note: '0-working/probe-security-programs.py reported vdp=none for this provider. That was a FALSE NEGATIVE
caused by two things: there is no /.well-known/security.txt (404), and the security contact on the HTML page
is obfuscated by Cloudflare email protection, so the keyword scan could not see an address. Manually
decoding the data-cfemail attribute on https://pixeltable.com/security yields a real, published security
contact. This artifact is therefore searched and hand-verified, and it must not be overwritten by a later
run of the probe script.'
policy:
- https://pixeltable.com/security
contact:
- security@pixeltable.com
security_txt:
served: false
path_probed: /.well-known/security.txt
status: 404
hosts_probed:
- https://www.pixeltable.com
- https://docs.pixeltable.com
note: 'RFC 9116 security.txt is NOT served on any host. No `SecurityTxt` pointer is emitted. This is the
single cheapest fix available to this provider: they already have the contact, they just do not serve it at
the machine-readable path where a scanner or agent would look.'
disclosure_program:
formal_program: false
bug_bounty: false
platforms_checked:
- HackerOne
- Bugcrowd
- Intigriti
platforms_found: []
published_process: 'If you believe you have found a security vulnerability or have any security concerns,
please contact us immediately at security@pixeltable.com. We appreciate your help in keeping Pixeltable
secure.'
safe_harbor: false
response_sla: null
note: 'A security contact and an invitation to report, but no structured VDP — no scope statement, no safe
harbour language, no disclosure timeline, no bounty.'
stated_security_practices:
source: https://pixeltable.com/security
authentication: 'Industry-standard authentication practices through WorkOS AuthKit, supporting secure login
methods including Single Sign-On (SSO) where applicable.'
encryption_in_transit: TLS
encryption_at_rest: 'Robust encryption standards provided by the underlying cloud infrastructure.'
infrastructure: 'Pixeltable Cloud runs on secure cloud infrastructure (e.g. AWS/GCP/Azure), benefiting from
their physical and network security measures.'
certifications: []
certifications_note: 'NONE CLAIMED. The security page names no SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP,
GDPR or CSA STAR certification, and no trust centre exists (trust.pixeltable.com does not resolve;
pixeltable.com/trust 404s). No `Compliance` and no `TrustCenter` pointer is emitted — an honest absence for
an early-stage company.'
evidence:
- source: https://pixeltable.com/security
kind: security-page
http_status: 200
fetched: '2026-08-17'
keywords:
- security vulnerability
- security concerns
- report
contact_extraction: 'decoded from data-cfemail Cloudflare email-protection attribute; both the cfemail
attribute and the /cdn-cgi/l/email-protection link decode to security@pixeltable.com'
- source: https://www.pixeltable.com/.well-known/security.txt
kind: security.txt
http_status: 404
fetched: '2026-08-17'
- source: https://pixeltable.com/status
kind: incident-channel
http_status: 200
fetched: '2026-08-17'
note: 'The status page also lists security@pixeltable.com as the channel to "report an incident or degraded
service", corroborating the address.'
- source: https://trust.pixeltable.com/
kind: trust-center
http_status: 0
fetched: '2026-08-17'
note: host does not resolve
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pixeltable-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.