Pixeltable · Vulnerability Disclosure

Pixeltable Vulnerability Disclosure

Vulnerability disclosure

Pixeltable runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyAi DataMultimodal AIAI Data InfrastructureVector SearchEmbeddingsRAGAgent MemoryMCPOpen-SourcePythonData OrchestrationComputed ColumnsVideo ProcessingMachine-Learning
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@pixeltable.com

Source

Vulnerability Disclosure

pixeltable-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-17'
method: searched
probe: true
source: https://pixeltable.com/security
note: '0-working/probe-security-programs.py reported vdp=none for this provider. That was a FALSE NEGATIVE
  caused by two things: there is no /.well-known/security.txt (404), and the security contact on the HTML page
  is obfuscated by Cloudflare email protection, so the keyword scan could not see an address. Manually
  decoding the data-cfemail attribute on https://pixeltable.com/security yields a real, published security
  contact. This artifact is therefore searched and hand-verified, and it must not be overwritten by a later
  run of the probe script.'
policy:
- https://pixeltable.com/security
contact:
- security@pixeltable.com
security_txt:
  served: false
  path_probed: /.well-known/security.txt
  status: 404
  hosts_probed:
  - https://www.pixeltable.com
  - https://docs.pixeltable.com
  note: 'RFC 9116 security.txt is NOT served on any host. No `SecurityTxt` pointer is emitted. This is the
    single cheapest fix available to this provider: they already have the contact, they just do not serve it at
    the machine-readable path where a scanner or agent would look.'
disclosure_program:
  formal_program: false
  bug_bounty: false
  platforms_checked:
  - HackerOne
  - Bugcrowd
  - Intigriti
  platforms_found: []
  published_process: 'If you believe you have found a security vulnerability or have any security concerns,
    please contact us immediately at security@pixeltable.com. We appreciate your help in keeping Pixeltable
    secure.'
  safe_harbor: false
  response_sla: null
  note: 'A security contact and an invitation to report, but no structured VDP — no scope statement, no safe
    harbour language, no disclosure timeline, no bounty.'
stated_security_practices:
  source: https://pixeltable.com/security
  authentication: 'Industry-standard authentication practices through WorkOS AuthKit, supporting secure login
    methods including Single Sign-On (SSO) where applicable.'
  encryption_in_transit: TLS
  encryption_at_rest: 'Robust encryption standards provided by the underlying cloud infrastructure.'
  infrastructure: 'Pixeltable Cloud runs on secure cloud infrastructure (e.g. AWS/GCP/Azure), benefiting from
    their physical and network security measures.'
  certifications: []
  certifications_note: 'NONE CLAIMED. The security page names no SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP,
    GDPR or CSA STAR certification, and no trust centre exists (trust.pixeltable.com does not resolve;
    pixeltable.com/trust 404s). No `Compliance` and no `TrustCenter` pointer is emitted — an honest absence for
    an early-stage company.'
evidence:
- source: https://pixeltable.com/security
  kind: security-page
  http_status: 200
  fetched: '2026-08-17'
  keywords:
  - security vulnerability
  - security concerns
  - report
  contact_extraction: 'decoded from data-cfemail Cloudflare email-protection attribute; both the cfemail
    attribute and the /cdn-cgi/l/email-protection link decode to security@pixeltable.com'
- source: https://www.pixeltable.com/.well-known/security.txt
  kind: security.txt
  http_status: 404
  fetched: '2026-08-17'
- source: https://pixeltable.com/status
  kind: incident-channel
  http_status: 200
  fetched: '2026-08-17'
  note: 'The status page also lists security@pixeltable.com as the channel to "report an incident or degraded
    service", corroborating the address.'
- source: https://trust.pixeltable.com/
  kind: trust-center
  http_status: 0
  fetched: '2026-08-17'
  note: host does not resolve

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pixeltable-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.