How it works Detection Roadmap Pricing Contact Install free
Security

Our commitment to transparent, responsible security.

How we handle vulnerabilities, what our security posture looks like, and what to expect when you report an issue to us.

Found a security issue? Please report it responsibly at security@phixo.io or use our vulnerability report form. We respond within 24 hours and we treat every report seriously.

Security Architecture

Phixo is designed with a minimal-trust, minimal-footprint architecture:

Responsible Disclosure Policy

We support the security research community and welcome responsible disclosure of vulnerabilities. If you discover a security issue in Phixo, we ask that you:

In return, we commit to:

Scope

In scope: Phixo Chrome extension, phixo.io and subdomains, backend API endpoints (api.phixo.io).

Out of scope: Third-party services we use (Stripe, Railway, Groq), social engineering attacks against Phixo employees, physical attacks, volumetric denial-of-service.

Security Acknowledgements

We thank the following researchers for responsibly disclosing security issues to us. This list will be updated as issues are reported and resolved.

No acknowledged researchers yet — be the first.

Report a Vulnerability

Use our secure vulnerability report form or email security@phixo.io. For sensitive reports, you may request our PGP public key.