Security Policy
Effective: 31 August 2026
Omega Image Pro uses a defense-in-depth design appropriate to a public no-account image-processing service.
Remote scan protections
Website scanning accepts HTTP/HTTPS public URLs only. The backend is designed to reject loopback, private, link-local, multicast and reserved IP destinations and to validate redirects to reduce server-side request forgery risk.
Upload handling
Uploads are subject to file-size, count, MIME/type and decoding checks. Generated filenames are server-controlled and temporary processing directories are not intended to execute uploaded scripts.
Rate limiting
Anonymous endpoints may use request-rate controls to protect availability and reduce abuse.
No promise of absolute security
No internet service can guarantee absolute security. Users should not submit secrets, credentials or highly confidential material that is unsuitable for temporary server processing.
Reporting
Report suspected vulnerabilities to support@omegaimagepro.com or legal@omegaimagepro.com. Please do not perform destructive testing against production infrastructure.