Skip to content
smallPict
Start Free
smallPictSecurity

Security is not a feature we bolt on—it's how we build.

smallPict converts each upload to WebP or AVIF and picks the quality per image. On Free and Starter, images are processed and not kept; on Pro and Business, optional Cloud Offload keeps your originals in encrypted cloud storage and serves the optimized files from the CDN.

Data encryption
TLS · AES-256
API key security
HMAC-SHA256
Infrastructure
Uptime target 99.9%
Privacy
Designed to follow GDPR & UU PDP

Data encryption

All data sent to and from SmallPict is encrypted in transit using TLS. Images and data we store are encrypted at rest using AES-256 in secure cloud storage. Uploads we don't keep (on plans without persistent storage, or on Pro and Business with Cloud Offload off) are held in temporary, encrypted processing storage and deleted automatically within 24 hours.

Infrastructure

SmallPict runs on established, enterprise-grade cloud infrastructure, and optimized images are delivered through our global CDN. Your data is protected with industry-standard encryption in transit (TLS) and at rest (AES-256). Consistent with standard security practice, we don't publish detailed infrastructure information, but we're happy to answer specific security questions from customers evaluating SmallPict.

API key security

Every API key is scoped to a single product line—WordPress or API/SDK—and cannot be used interchangeably. Keys are never displayed in full after initial creation, and can be rotated at any time from your dashboard.

Credentials for your own storage and CDN

If you connect your own storage and CDN accounts to SmallPict (Velocity and Momentum plans), your credentials are stored in an encrypted secrets manager, never in our application database, and are never returned in full through any API response or dashboard view. SmallPict staff cannot view your raw credentials.

Access control

Internal access to customer data is role-restricted and logged. Every administrative action—including account changes, refunds, or support access—is recorded in an audit trail.

Privacy & data protection

SmallPict's data handling practices are designed to align with GDPR (for EU users) and Indonesia's Personal Data Protection Law (UU PDP No. 27/2022). See our Privacy Policy for full details.

Responsible disclosure

Found a security issue? We want to know. Email security@smallpict.app with details, and we'll respond as quickly as possible. Please do not publicly disclose a vulnerability before we've had a chance to address it.

security@smallpict.app