Photo Privacy Lab
Security policy
The highest-value assets are selected image bytes, extracted private metadata, generated derivatives, and the integrity of the browser-delivered application.
Current security boundary
Only static build output is deployed. There is no image upload route, server image processor, database, account session, or secret in browser code. Imported file bytes are treated as untrusted and parsed with format signatures, length checks, and bounded offsets.
Browser controls
The deployed site uses a restrictive content security policy, framing protection, MIME sniffing protection, a limited permissions policy, and no third-party script origins in version 1.
Reporting a vulnerability
Do not include a real private photograph in a report. Use a synthetic fixture, describe the impact, and send sensitive details through the source repository private vulnerability reporting form rather than a public issue.