pixmoat / legal
Security
Last updated: 12 August 2026
pixmoat is designed to reduce the risk of accidental visual regressions while protecting account and project data. This page describes our approach at a high level and intentionally does not disclose sensitive infrastructure details.
Current controls
- Encrypted HTTPS connections for website and service traffic.
- Authentication and access controls for accounts, projects, and administrative functions.
- Separate handling of payment details through Creem; pixmoat does not store payment card numbers.
- Hosted infrastructure and database operations on Netcup-managed infrastructure controlled by the operator.
- Logging and monitoring intended to detect operational and security problems.
- Backups and recovery procedures appropriate to the deployed service configuration.
Customer responsibilities
Use strong unique credentials, protect project tokens, limit team access, avoid uploading unnecessary personal or regulated data, and report suspected compromise promptly.
Reporting a vulnerability
Report security issues privately to info@pixmoat.com. Include enough information to reproduce the issue, but do not include real customer data or secrets. We will acknowledge reports when possible and coordinate a reasonable fix and disclosure timeline.
Security limitations
No service can guarantee absolute security. Controls, providers, and infrastructure may change as pixmoat develops. Customers should assess whether pixmoat is appropriate for their data and risk profile.