ReferencesVulnerability Reporting

Vulnerability Reporting

Imgix takes the security of our platform seriously. If you believe you have discovered a security vulnerability in our systems, we encourage you to report it to us responsibly.

How to Report a Vulnerability

To report a potential vulnerability, please send an email to support@imgix.com with the subject line “Vulnerability Report”. Include the following in your report:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact of the vulnerability
  • Any suggested remediation steps

We will acknowledge receipt of your report and work to triage and address confirmed vulnerabilities in a timely manner.

Compensation

Imgix does not operate a formal bug bounty program and does not guarantee monetary compensation for vulnerability reports.

We evaluate all reports on a case-by-case basis. While we appreciate the efforts of security researchers, we cannot commit to any specific reward or recognition in exchange for reports.

Out of Scope

The following categories are outside the scope of our vulnerability reporting process:

  • Social engineering attacks targeting Imgix employees or customers
  • Physical security vulnerabilities
  • Denial of service (DoS/DDoS) attacks
  • Vulnerabilities in third-party services not controlled by Imgix
  • Issues that require physical access to a user’s device
  • Spam or email phishing campaigns

Responsible Disclosure

We ask that you:

  • Do not publicly disclose the vulnerability before we have had the opportunity to address it
  • Do not exploit the vulnerability beyond what is necessary to demonstrate the issue
  • Do not access or modify data belonging to other users

We are committed to working with researchers who follow responsible disclosure practices.