Third Party Index

Snapshot 17963

Document
Security page
URL
https://www.pixiebrix.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
51577 bytes
SHA-256 (raw)
8e8e65dc5f30e464e8c3f9aab7afc9c57cbb9a20bd7295f2f83290e18b538840
SHA-256 (normalized text)
bb42e9ee0f8375251e02b8528d8a268b21e71ce3c2270968f13b06a60a1ecb48

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security and compliance overview
It's a top priority at PixieBrix to keep your data safe and compliant with your organization's policies. This page provides an overview of the measures we take and the controls available to you.
View Trust Center
Privacy
The best way to protect data is to avoid accessing or transmitting it in the first place. We only transmit and store data required to provide our services. Data from websites you visit never leaves your browser unless you tell it to.
Our Privacy and Security policy provides complete details on what data is accessed, transmitted, and stored.
Hosting
Our web application is hosted in the United States, on Salesforce Heroku (Common Runtime). Heroku is built on Amazon Web Services. We also use Amazon S3 for hosting public media uploads (e.g., Marketplace screenshots).
Our Privacy and Security policy provides a complete list of our service providers.
Encryption at rest
Web application data is encrypted at rest with AES-256, block-level encryption.
Encryption in transit
All internal web application traffic and traffic between the browser extension and web application is encrypted with transport layer security (TLS). You can check the encryption status with Qualys SSL Labs.
Backup and disaster recovery
Web application data is automatically backed up and can be rolled back up to four (4) days.
Vulnerability scanning
We run regular API and site vulnerability scans with Intruder. Our software dependencies are automatically scanned for vulnerabilities using GitHub's Dependabot. We use static analysis tools, such as GitHub Advanced Security and bandit to continuously scan our source code for potential vulnerabilities.
Web application monitoring and protection
The Web Application is protected by Datadog's Application Security Management. Datadog ASM identifies and blocks the OWASP Top 10 and business logic attacks in real-time.
We additionally use security headers, including content security policy (CSP) headers, to protect users from attacks. You can check our web application's score on SecurityHeaders.io.
Identity and access management (IAM)
We support Google OAuth2, Microsoft OAuth2, and SSO authentication for authenticating with the web application. We encourage you to enable/enforce two-factor authentication (2FA) for your account/organization.
Enterprise administrators can choose to authenticate users from their email domain, or to limit access to a specific set of users. Additionally, enterprises can use role-based access control (RBAC) and group-based access control (GBAC) to control which mods users can view, edit, and activate.
Authentication with other services
Private configurations for third-party APIs are stored locally in your browser. In addition to API key and token authentication, we support OAuth2 authentication via the browser's identity API.
Our framework provides fine-grained controls for what API calls are authenticated. See our documentation for more information.
For securely accessing legacy APIs that lack user access controls, we optionally provide an API Gateway. The credentials are stored encrypted in our web application and are only accessible to your organization's admins.
Browser extension permissions
Access to your browser data is enforced by your browser's built-in protection mechanisms. Wherever possible, we request permissions only when you enable a feature that requires those permissions. See our Privacy and Security Policy for a detailed list of what permissions the browser extension requests, when, and why.
Our framework provides additional controls for what websites our extension can access and with which services it can authenticate. See our documentation for more information.
Third-party review
We have completed our SOC 2 Type 2 with the guidance of third-party audit firm A-LIGN.
Additionally, we complete an annual independent penetration test and Google Cloud Application Security Assessment (CASA).
Each version of the browser extension published in the Chrome Web Store is reviewed by Google. See Chrome Developers: Frequently Asked Questions for more information on Chrome Web Store review process.
Additionally, we encourage independent security review via our responsible disclosure policy.
Frequently asked questions
Everything you need to know about the product and billing.
Are you SOC-2 or ISO/IEC 20071 certified?
We have completed our SOC 2 Type 2 audit with third-party audit firm A-LIGN. Our SOC 2 covers the Security, Availability, and Confidentiality trust criteria. We have not yet completed an ISO/IEC 20071 certification.
We work with enterprise customers to meet their compliance obligations. For example, we can represent our security practices in enterprise contracts.
For access to our SOC 2 Type 2 report and other confidential security information, contact [email protected].
Are you HIPAA compliant?
Our services are HIPAA-eligible – they can be configured and used in a way that is HIPAA compliant. The most common way is to configure our services to not access pages with Protected Health Information (PHI), or to only transmit PHI directly between the user's browser and a HIPAA compliant service.
We work with enterprise customers to meet their HIPAA compliance obligations. For example, we are able to execute Business Associate Agreements (BAAs) and represent our security practices.
Are you California Consumer Privacy Act (CCPA) compliant?
We are currently exempt from and do not attest to compliance with all provisions of the California Consumer Privacy Act (CCPA). However, we do comply with most of the provisions and are working to officially attest to compliance.
Our Privacy and Security Policy enumerates what personal information we collect and how it is used. We never sell your personal information, so there's nothing to opt-out of. To request what information we have about you, or to delete your account and personal information, contact [email protected].
Are you EU General Data Protection Regulation (GDPR) compliant?
Yes, we are GDPR compliant. For our standard Data Processing Agreement (DPA), refer to our Terms and Conditions.
Data is processed in the United States and EU under the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
‍
Additionally, we are able to execute custom Data Processing Agreements (DPA) with enterprise customers to ensure they meet their GDPR and compliance obligations. For more information, contact [email protected] or your Account Executive.
To make a Data Subject Access Request (DSAR), contact [email protected]
Are you Children's Online Privacy Protection (COPPA) Rule compliant?
We created PixieBrix for the exclusive use of adults (18 and older). We don’t knowingly collect or solicit personal information from children. If you are a child under 18, please do not attempt to register for our products or send any personal information to us.
Do you have a bug bounty program?
We do not have a bug bounty program and do not pay monetary rewards for reporting security vulnerabilities. If you discover a vulnerability, please follow our Responsible Disclosure instructions.
Still have questions?
Can't find the answer you're looking for? Please chat to our friendly team
Contact Us
Product
Platform
Solutions
Data Loss Protection
Account Abuse
Investigation & Audit
Revenue Protection
Resources
Blog
Certification
Compare
Documentation
Learning Center
Pricing
Resources
Templates
Tutorials
About
Contact
Cookie Policy
Glossary
Pricing
Privacy
Security
Terms
Trust Center
2026 PixieBrix, Inc.
2026 PixieBrix, Inc.