generated: '2026-08-17' method: searched probe: true source: https://pixeltable.com/security note: '0-working/probe-security-programs.py reported vdp=none for this provider. That was a FALSE NEGATIVE caused by two things: there is no /.well-known/security.txt (404), and the security contact on the HTML page is obfuscated by Cloudflare email protection, so the keyword scan could not see an address. Manually decoding the data-cfemail attribute on https://pixeltable.com/security yields a real, published security contact. This artifact is therefore searched and hand-verified, and it must not be overwritten by a later run of the probe script.' policy: - https://pixeltable.com/security contact: - security@pixeltable.com security_txt: served: false path_probed: /.well-known/security.txt status: 404 hosts_probed: - https://www.pixeltable.com - https://docs.pixeltable.com note: 'RFC 9116 security.txt is NOT served on any host. No `SecurityTxt` pointer is emitted. This is the single cheapest fix available to this provider: they already have the contact, they just do not serve it at the machine-readable path where a scanner or agent would look.' disclosure_program: formal_program: false bug_bounty: false platforms_checked: - HackerOne - Bugcrowd - Intigriti platforms_found: [] published_process: 'If you believe you have found a security vulnerability or have any security concerns, please contact us immediately at security@pixeltable.com. We appreciate your help in keeping Pixeltable secure.' safe_harbor: false response_sla: null note: 'A security contact and an invitation to report, but no structured VDP — no scope statement, no safe harbour language, no disclosure timeline, no bounty.' stated_security_practices: source: https://pixeltable.com/security authentication: 'Industry-standard authentication practices through WorkOS AuthKit, supporting secure login methods including Single Sign-On (SSO) where applicable.' encryption_in_transit: TLS encryption_at_rest: 'Robust encryption standards provided by the underlying cloud infrastructure.' infrastructure: 'Pixeltable Cloud runs on secure cloud infrastructure (e.g. AWS/GCP/Azure), benefiting from their physical and network security measures.' certifications: [] certifications_note: 'NONE CLAIMED. The security page names no SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, GDPR or CSA STAR certification, and no trust centre exists (trust.pixeltable.com does not resolve; pixeltable.com/trust 404s). No `Compliance` and no `TrustCenter` pointer is emitted — an honest absence for an early-stage company.' evidence: - source: https://pixeltable.com/security kind: security-page http_status: 200 fetched: '2026-08-17' keywords: - security vulnerability - security concerns - report contact_extraction: 'decoded from data-cfemail Cloudflare email-protection attribute; both the cfemail attribute and the /cdn-cgi/l/email-protection link decode to security@pixeltable.com' - source: https://www.pixeltable.com/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-17' - source: https://pixeltable.com/status kind: incident-channel http_status: 200 fetched: '2026-08-17' note: 'The status page also lists security@pixeltable.com as the channel to "report an incident or degraded service", corroborating the address.' - source: https://trust.pixeltable.com/ kind: trust-center http_status: 0 fetched: '2026-08-17' note: host does not resolve