Third Party Index

Snapshot 52394

Document
Security page
URL
https://www.tiny.cloud/tinymce/security/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
285320 bytes
SHA-256 (raw)
66fb1c77e022a8f46fb7308fac49c293cc8e1674c8a0948f81796c2e556bc055
SHA-256 (normalized text)
8e2ec4b5f3f6e8e077f961044761e56ff2ae629f9fdcadbfa9953aa5a437951e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

TinyMCE
The world's most trusted WYSIWYG HTML editor, for total control over your rich text editing.
Overview
Features
Pricing
Documentation
Demos
Download TinyMCE for Free
TinyMCE AI
Multi-turn chat, inline rewrites, and automated quality checks — all document-aware.
Media Optimizer
Compress and resize images and videos automatically on upload, directly in the editor.
MoxieManager
Media file management simplified in a PHP or .NET environment.
Start trial
Try every feature for free!
Start for free
Developer Center
Explore frameworks, solutions, and technical guides for building with TinyMCE.
Frameworks
Use Cases
Support
License Keys
Editor Loads
Submit a Support Request
Documentation
In-depth documentation to help you develop with and customize Tiny products.
Getting Started
Basic Setup
API Reference
Migrating to TinyMCE
Download TinyMCE Free
Start trial
Try every feature for free!
Start for free
Use Cases
Out-of-the-box editor with infinite use cases and complete design flexibility.
Content Management System
Email and Messaging Platform
Document Management System
Customer Relationship Management
Learning Management System
Internal & SaaS Applications
Workflow & Collaboration
Roles
Developer
Product Manager
Senior Manager
SecurityHostingCustomizationFrameworks & Integrations
Start trial
Try every feature for free!
Start for free
Blog
Read the world's best blog on WYSIWYG HTML editors, rich text editing, and insights on building SaaS application editors.
Events & Webinars
Explore upcoming and on-demand events and webinars to unlock the full potential of TinyMCE.
Case Studies
Discover why industry leaders and scaling start-ups love, use and trust Tiny products.
White Papers and Reports
See how Tiny improves ROI, grows revenue and saves development costs.
Read:
Buy vs Build: The Great Debate White Paper
Opportunity Cost of Technical Debt
The State of Rich Text Editors 2025 Report
Start trial
Try every feature for free!
Start for free
PricingContact Us
Log InStart Free Trial
The most secure rich text editor
SOC 2 and GDPR compliant. Trusted by 1.5M+ developers. Used in 100M+ apps.
Ensure data security, availability and confidentiality
Trusted in over 100 million products spanning security-conscious industries such as finance, government, healthcare and education, TinyMCE simplifies security audits with SOC 2 Type 2 certification and GDPR compliance.
Is data security a concern for your
HTML text editor?
Cloud Security
"Tiny Cloud" is Tiny's Cloud-hosted version of TinyMCE, its features and its services. Users of Tiny Cloud access TinyMCE using a tiny.cloud URL containing their API Key. The following data are associated with an API Key:
JWT authentication for Tiny Drive (existing customers)
Custom dictionaries for Spell Checker
Allowed domains
A set of allowed features, depending on your subscription plan
Tiny Cloud is a multi-tenanted system comprised of the following components:
Tiny Cloud Distribution
Tiny Cloud Services
Tiny Cloud services are designed to comply with GDPR regulations, ensuring that any data processed is handled according to the stringent requirements set forth by GDPR.
Tiny Cloud Distribution
This is a distribution frontend hosted by AWS CloudFront. It serves TinyMCE and associated script, style and image files. When serving TinyMCE, Tiny Cloud pre-configures TinyMCE to add the following:
Metrics tracking
Configuration for Tiny Cloud Services
Tiny Cloud Distribution restricts access based on:
The API Key (part of the URL path)
The features enabled on that API Key
The HTTP Referer header
If you’re not entitled to a feature, requests to URLs which require that feature will either return a HTTP error code or a "dummy" version of the resource you requested. The dummy versions typically display an error message.
The HTTP Referer must match an Allowed Domain configured on your account. Allowed Domains can be configured via the Tiny Account website.
Browsers that do not send a HTTP Referer (such as Brave) are not compatible with Tiny Cloud Distribution.
Note: Tiny does not consider an API Key to be private or sensitive data.
Tiny Cloud Services
Tiny Cloud Services adhere to GDPR guidelines, ensuring data privacy and protection in all Cloud hosted components.
Tiny Cloud CDN
Tiny Cloud Services are Cloud-hosted server-side components used by TinyMCE. They're the Cloud equivalent of the Self-hosted services, and overlap in functionality.
Metrics tracking
Configuration for Tiny Cloud Services
Tiny Cloud Services restrict access based on:
The API Key (part of the URL path)
The features enabled on that API Key
The HTTP Referer header
Cookies
TinyMCE, TinyMCE Premium Plugins, TinyMCE Server-Side Components and Tiny Drive do not make use of cookies.
TinyMCE's website https://www.tiny.cloud/ does use cookies for collecting marketing data.
TinyMCE’s website uses cookies in compliance with GDPR. Users can manage their cookie preferences via our cookie management tool.
For more information on security, visit the TinyMCE docs.
Self-Hosted Security
Security-sensitive customers (like those in regulated industries), may want to consider using TinyMCE Self-Hosted. This solution gives you full control over the hosting and data processed. Data processed using these systems is not sent to any servers that Tiny controls – you host the core editor and premium plugins on your own infrastructure.
Certain TinyMCE features/plugins may however access external services - a detailed list is available from your Account Manager. However, all of these features are able to be disabled, should they not fit within your risk profile.
The server-side components restrict access based on configurable CORS allowed origins, while some services additionally provide authentication based on JWT.
For security-sensitive customers, TinyMCE Self Hosted Security solutions comply with GDPR, giving you full control over data processed on your infrastructure without it being sent to Tiny’s servers.
Cookies
TinyMCE, TinyMCE Premium Plugins, TinyMCE Server-Side Components and Tiny Drive do not make use of cookies.
TinyMCE's website https://www.tiny.cloud/ does use cookies for collecting marketing data.
For more information on security, visit the TinyMCE docs.
Scripts and XSS vulnerabilities
TinyMCE filters content such as scripts from the editor content, however, client-side applications can be by-passed by attackers. Tiny recommends processing received editor content through server-side filters.
SVGs (Scalable Vector Graphics) are not supported in TinyMCE to protect our users and their end-users. SVGs can be used to perform both client-side and server-side attacks.
TinyMCE can be used with a Content Security Policy (CSP) header.
From the 1st of January 2020, Security Advisories for patched XSS vulnerabilities will be published on the TinyMCE GitHub repository Security page. For more information on security, visit the TinyMCE docs.
TinyMCE supports user rights under GDPR, including the right to access, rectify, and erase personal data. Users can exercise these rights through our dedicated support channels.
Security Scanning, Testing and Reporting
TinyMCE uses industry-leading tools to scan code for problematic code patterns or known vulnerabilities from third parties. Dependencies are updated before the next version (major or minor) is released.
Tiny's products are predominantly written in statically-typed, memory-safe languages, which inherently reduces risk of runtime errors and vulnerabilities related to memory use.
Tiny values the work of security researchers in improving the security of technology products worldwide. We welcome researchers who wish to responsibly disclose vulnerabilities in our products or systems. Note that we do not offer any “bug bounty” program or any form of payment for disclosed vulnerabilities. If you would like to report a vulnerability, please email infosec@tiny.cloud
In compliance with GDPR, TinyMCE has established data breach protocols to ensure timely notification to users and authorities in the event of a data breach.
For more information on security, visit the TinyMCE docs.
FAQs
How does Tiny ensure the security of its products?
We maintain the following staffing and security process protocols:
Dedicated InfoSec Team
Continuous automated Codescans during development and post release
Automated Static analysis code scans
Peer code reviews
Manual and automated QA assurance process
Network of security researchers, developers and customers reporting security vulnerabilities
Annual Pen tests conducted by an independent security firm
Frequent patch releases and security updates
GDPR compliance in data security and processing practices.
How do I report a security vulnerability to Tiny?
Please forward all security reports to infosec@tiny.cloud. The report should include a replication case so we can reproduce the vulnerability. This covers all security matters relating to Tiny's digital presence - including websites, blogs, product portals and all software products.
The Tiny InfoSec Team reviews all vulnerability reports sent to infosec@tiny.cloud. Once Tiny has completed its review and can replicate the issue, we will share a remediation response plan with you and discuss public disclosure time frames.
What is Tiny’s vulnerability disclosure policy?
Tiny has a 90-day disclosure policy once a vulnerability has been verified. After a security patch has been released, Tiny will disclose the vulnerability through these public sources:
Mitre CVE
Github GHSA
Product release notes
Does Tiny offer a bounty or reward for finding security vulnerabilities?
Tiny does not offer any cash rewards or bounties for finding security vulnerabilities. Once a vulnerability has been verified and patched, Tiny will attribute you as the finder for the security vulnerability in Tiny’s public disclosure.
Does TinyMCE allow me to customize any security configuration options?
To further enhance security for customers integrating TinyMCE into their applications, we offer customizable security configuration options to suit different use cases. See our Security Guide documentation for details.
How does Tiny ensure GDPR compliance?
TinyMCE ensures compliance with the European Union General Data Protection Regulation (GDPR) EU 2016/679 by implementing robust GDPR data protection measures. This includes data encryption, secure storage, and strict access controls. We also provide clear user consent mechanisms and allow users to exercise their rights under GDPR, such as data access, rectification, and erasure.