Secure by design

Security and responsible disclosure

Our browser, dependency and deployment safeguards—and how to report a vulnerability without sending private imagery.

01

Application safeguards

File extensions are not trusted. Parsers validate segment and chunk boundaries, metadata is rendered as text, SVG is not accepted as an image input, and CSV exports neutralize spreadsheet formulas.

  • 25 MiB and 80 MP limits
  • Worker isolation for parsing
  • Sanitized download names
  • No innerHTML for metadata
  • Security headers in hosted responses
02

Report a security issue

Send a concise description to security@analyzeimage.com when the public mailbox is activated. Include reproduction steps and impact, but do not attach a private user image, credentials or secrets. No bug bounty is currently promised.

Put the model to work

Inspect an image without creating an upload.

Open metadata viewer