Security & trust

Security claims should be inspectable, not decorative.

ImgNimble separates on-device tools, anonymous secure-worker jobs and paid-provider operations; uses expiring result downloads; and keeps private application storage outside the public web root.

Controls in this release

  • Admin RFC 6238 two-factor authentication and single-use recovery codes.
  • CSRF protection, native PDO prepared statements, login throttling and protected session cookies.
  • Per-route CSP profiles, frame blocking, nosniff, referrer policy and optional HSTS after HTTPS verification.
  • Worker HMAC signatures, timestamped requests, per-app identity and private temporary staging under storage/.
  • 24-hour cleanup policy with deletion audit and tokenized result downloads.
  • Append-only admin audit records and a daily backup CLI with retention metadata.

Responsible disclosure

Security reports: hello@imgnimble.com. Also see security.txt and Privacy Proof.

Third-party ratings

No third-party rating evidence is configured. ImgNimble does not invent a score or review count.

What we do not claim

This page does not claim SOC 2, ISO 27001, penetration-test certification, government approval or biometric certification unless such evidence is later added and linked.