Security
UNBG's security starts with its architecture. Your images never leave your browser, and there are no accounts, no database and no image-processing server, so there is very little for anyone to steal from us.
This page explains the other protections, what they don't cover, and how to report a problem.
What the design rules out
- No uploads. Images, masks, results and filenames are not sent anywhere. An automated test checks this before each release.
- No stored images. Nothing you process is written to browser storage.
- No accounts or passwords. There is nothing to leak or reuse.
- No image links. UNBG only accepts files from your device. It never fetches images from web addresses.
Browser protections
UNBG's pages are sent with security headers that tell your browser to block risky behaviour:
- Content Security Policy. Scripts may only come from unbg.me. Third-party scripts are blocked, the page cannot be embedded in other sites (
frame-ancestors 'none'), and forms and plugins are switched off. - Strict-Transport-Security. Your browser always uses HTTPS for unbg.me.
- X-Content-Type-Options: nosniff. Files are only treated as the type they say they are.
- Referrer-Policy: no-referrer. Sites you follow a link to aren't told which UNBG page you came from.
- Permissions-Policy. Features UNBG doesn't need, such as the camera, microphone and location, are switched off.
- Cross-origin isolation (COOP, COEP, CORP). Our files can't be pulled into other sites' pages, other windows can't script ours, and the page can only load resources that opt in.
You can inspect the exact headers yourself with your browser's developer tools (Network tab, select any request, then Headers). The Content Security Policy is:
default-src 'none';
script-src 'self' 'wasm-unsafe-eval';
style-src 'self';
img-src 'self' blob:;
font-src 'self';
connect-src 'self';
worker-src 'self';
manifest-src 'self';
media-src 'none';
object-src 'none';
frame-src 'none';
child-src 'self';
base-uri 'none';
form-action 'none';
frame-ancestors 'none';
upgrade-insecure-requestsThe live policy also lists SHA-256 hashes for the few small inline scripts that start the page, so that no other inline script can run. 'wasm-unsafe-eval' lets the browser compile the AI engine's WebAssembly; it does not allow JavaScript eval().
Safe handling of image files
- Files are identified by their contents, not by their name or extension. Only still JPG, PNG and WebP images are accepted. SVG, which can contain scripts, is rejected.
- Size limits (48 MB and 60 megapixels) protect your browser from "decompression bomb" images that expand to enormous sizes.
- Filenames are cleaned before they are displayed or used in downloads, so an odd filename can't inject code or create unexpected paths inside a ZIP.
- Heavy work runs in a separate Web Worker, isolated from the page.
Verified AI model
- The model version is pinned to an exact upstream revision (
dc4edd9f7623961aa5ae2b186c1b428f4ed38d6a). - Every model and engine file has a SHA-256 fingerprint in UNBG's model manifest. UNBG checks each file against it in your browser before use, including copies loaded from the cache. A tampered or corrupted file is rejected, not run.
- New model versions get new, versioned file addresses, so a cached old file can never be mixed with a new one.
Software supply chain
- Dependencies are pinned with a lockfile and checked with automated vulnerability and licence audits before release.
- We prefer small, well-maintained libraries and avoid code we can't audit.
- The model and all dependencies are under permissive licences. See open-source licences.
Hosting
UNBG is a static website on Cloudflare. There is no server-side code that could receive your images; the host only serves fixed files.
What we can't protect against
- Your device and browser. If your device, browser or a browser extension is compromised, it may be able to see anything on your screen, including your images. Only install extensions you trust.
- Shared computers. Downloaded results are saved in your normal downloads folder, where other users of the same computer may see them.
- Copies you make. Once you download or share a result, it is outside UNBG's control.
Report a vulnerability
If you think you've found a security problem, please email [security contact email: to be confirmed] with the steps to reproduce it. Please don't include private images. Our contact details are also published in security.txt.
- We aim to acknowledge reports within [acknowledgement time: to be confirmed].
- Please give us reasonable time to fix an issue before disclosing it publicly.
- We won't take legal action against good-faith research that respects this page, avoids harming other users and doesn't degrade the service. [safe-harbour wording: to be confirmed by legal review]
- There is currently no paid bug bounty.