← Grabbing The Vid
GRABBING THE VID · POLICY
Security
Security controls are designed to reduce abuse, server-side request risks, credential exposure, and uncontrolled media retention.
Application controls
- Supported-host allowlisting and HTTPS-only URL validation.
- Rejection of credentials and unsafe/private destination addresses.
- Rate limiting for analysis and job creation.
- Security headers including content-type sniffing, framing, referrer, and permissions restrictions.
Processing controls
- Background processing is separated from the web request path.
- Media processing runs in isolated temporary directories.
- Output-size checks are enforced.
- Secrets are supplied through environment variables rather than repository files.
Storage controls
- Completed files are kept only in temporary Render server storage while a job is being processed or the download is being delivered.
- Downloads use a direct temporary download response from the API.
- The application deletes the completed file after the download response and removes stale job directories after the configured TTL.
Reporting
Security reports should be sent through the monitored security contact point published before launch. Do not publicly disclose an exploitable vulnerability before there is an opportunity to investigate it.