Trust center
Security at Drawtryix
Learn about Drawtryix account, storage, asset, browser, and AI-pipeline security practices and how to report a vulnerability responsibly.
Effective August 6, 2026
Private storage
Profile-scoped access
Asset inspection
Security practices
- Encrypted HTTPS connections and strict transport security.
- Private object storage, database row-level security, and profile ownership checks.
- Short-lived signed asset URLs rather than permanent public files.
- Server-only AI and storage credentials; privileged secrets are not shipped to the browser.
- Restricted browser capabilities, framing protection, content security policy, and referrer controls.
- Upload, image, model, request-size, quota, and concurrency limits.
- Content moderation, metadata removal, and generated-asset validation.
- Replay-safe job identities and provider callback verification.
No service can guarantee perfect security. Safeguards are reviewed and updated as the product, providers, and identified risks change.
Report a vulnerability
Please report suspected vulnerabilities privately. Do not include children's drawings, names, access tokens, passwords, or other unnecessary personal information. Do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and protect families.
Email contact@noctryix.com with “Drawtryix security report” in the subject, or use the Noctryix contact form.
Our machine-readable disclosure instructions are available at /.well-known/security.txt.
