Effective Date: 30 August 2026 Last Updated: 30 August 2026
Pixiera is designed with security and privacy considerations incorporated into the operation of its Services.
This page provides a high-level description of security practices. To protect Pixiera, its customers, and its infrastructure, Pixiera does not publicly disclose sensitive technical details that could materially increase security risk.
1. SECURITY PRINCIPLES
Pixiera seeks to maintain technical and organizational measures appropriate to the risks associated with its Services.
Depending on the applicable system and risk, such measures may include:
- authentication;
- authorization;
- access control;
- least-privilege practices;
- tenant separation;
- encryption in transit;
- encryption at rest where appropriate;
- logging;
- monitoring;
- backups;
- incident response;
- controlled administrative access; and
- vendor and infrastructure controls.
2. TECHNOLOGY INFRASTRUCTURE
Pixiera currently relies on selected third-party infrastructure and technology providers, including:
Supabase
Supabase may provide database, authentication, storage, and related backend services.
Vercel
Vercel may provide website hosting, deployment, edge delivery, and related infrastructure.
Cloudflare
Cloudflare may provide DNS, network, security, traffic management, performance, and related infrastructure services.
Stripe
Stripe may provide payment processing and billing infrastructure.
Resend
Resend may provide transactional email delivery infrastructure.
OpenAI
OpenAI may provide AI processing capabilities used by selected Pixiera features.
The specific role of each provider may differ according to the Pixiera feature and technical architecture.
3. TENANT AND DATA ISOLATION
Pixiera is designed to restrict Customer Data according to authorization and tenant boundaries.
Pixiera does not publicly disclose implementation details of access controls, database architecture, authentication mechanisms, internal identifiers, network configuration, secrets management, or other security-sensitive implementation details where doing so could increase security risk.
Actual security architecture may evolve over time.
4. ACCESS CONTROL
Access to systems is restricted according to role, authorization, and business need.
Administrative access may be subject to additional controls.
Pixiera seeks to apply least-privilege principles where appropriate.
5. SECRETS AND CREDENTIALS
Sensitive credentials, API keys, authentication tokens, encryption materials, and other secrets are intended to be managed through controlled mechanisms appropriate to the relevant environment.
Pixiera does not intentionally expose sensitive credentials through public client-side code or publicly accessible interfaces.
6. ENCRYPTION
Pixiera seeks to use appropriate encryption and transport security measures to protect information in transit and, where appropriate, at rest.
The exact algorithms, configurations, key-management architecture, and implementation details are not publicly disclosed where doing so could create security risk.
7. LOGGING AND MONITORING
Pixiera uses logging and monitoring intended to identify:
- unusual activity;
- security events;
- application failures;
- operational problems;
- abuse;
- unauthorized access attempts; and
- service degradation.
8. BACKUPS AND RECOVERY
Where appropriate, Pixiera maintains backup and recovery mechanisms intended to support service continuity and restoration.
Specific backup architecture, retention schedules, geographic redundancy, and recovery procedures are not publicly disclosed where doing so could create unnecessary security or operational risk.
9. INCIDENT RESPONSE
Pixiera maintains processes intended to:
- detect incidents;
- contain affected systems;
- investigate;
- assess impact;
- remediate;
- restore Services; and
- notify affected parties where legally required.
Where applicable law requires notification to authorities, customers, or affected individuals, Pixiera will comply with the applicable legal requirements.
10. THIRD-PARTY PROVIDER RISK
Pixiera relies on selected third-party service providers and infrastructure partners.
Pixiera seeks to evaluate relevant providers according to appropriate security, privacy, contractual, technical, and operational considerations.
Providers may be changed or replaced as the Services evolve.
Where legally or contractually required, material processor or subprocessor changes will be handled through the applicable notification process.
11. AI SECURITY
AI-enabled workflows are subject to applicable access controls and authorization mechanisms.
Where Pixiera allows AI to prepare or execute business actions, Pixiera seeks to use authorization and workflow controls designed to reduce unauthorized execution.
Customer remains responsible for configuring automated workflows appropriately for the risk associated with those workflows.
12. PAYMENT SECURITY
Payment transactions may be processed by Stripe.
Where Stripe processes payment-card information directly, Pixiera generally does not need to store full payment-card information.
Payment processing is subject to the applicable payment provider's systems, terms, and privacy practices.
13. RESPONSIBLE DISCLOSURE
Security vulnerabilities may be reported to:
Please include:
- affected URL or feature;
- description of the vulnerability;
- reproduction steps where possible;
- potential impact; and
- relevant technical information.
Please do not intentionally access, modify, delete, or disclose information belonging to another user.
14. SECURITY CERTIFICATIONS AND ATTESTATIONS
Pixiera will not claim SOC 2, ISO 27001, penetration testing, security certification, formal audit, or other security attestations unless such status actually exists and has been verified.
15. NO ABSOLUTE SECURITY GUARANTEE
No internet-connected service can guarantee absolute security.
Pixiera nevertheless seeks to maintain safeguards appropriate to the nature, scope, and risks of its Services.
16. CONTACT
Security questions may be sent to:
Privacy questions may also be sent to:
