Core Security Principles
1. In-Browser Image Processing
Whenever you upload a photograph to PixPassport, initial image inspection, local previews, and size pre-compression (down to ≤ 3 MB) occur directly inside your browser via standard HTML5 Canvas and Web APIs.
This ensures your uncompressed high-resolution original file never leaves your computer or phone unnecessarily, minimizing bandwidth and exposure.
2. Encrypted Transmission (TLS 1.3 / HTTPS)
When processing requires automated biometric alignment and background formatting, your image payload is transmitted over an encrypted HTTPS connection utilizing modern Transport Layer Security (TLS 1.3) protocols.
HTTP Strict Transport Security (HSTS) is enforced to ensure man-in-the-middle attacks and protocol downgrades are prevented.
3. Zero Permanent Storage & Automatic Deletion
PixPassport does not maintain a permanent facial database, biometric repository, or photo gallery of uploaded images.
Images sent for processing exist in ephemeral memory only for the brief duration required to detect face boundaries, crop, and generate the final print output. Once the session is concluded, server-side processing artifacts are automatically deleted.
4. Server-Side Security Isolation
All interactions with backend processing services are isolated inside Next.js server-side route handlers (/api/passport-photo).
Secret API keys, credentials, and internal endpoints are never exposed to client browsers or visible in network inspection tools.
5. Payment Processing Security
Payment transactions are conducted through accredited, PCI-DSS Level 1 compliant payment service providers.
PixPassport never handles, processes, or stores your raw credit or debit card numbers, CVVs, or banking credentials on our web servers.
6. User Privacy Rights & Client Storage Control
Result previews and session references are kept in your browser’s temporary sessionStorage and localStorage.
You can instantly purge all locally stored references at any time simply by closing your browser tab or clearing your browser site data. Under the UK GDPR, you have the right to request confirmation of any data processed or request technical support assistance.
Security Contacts & Inquiries
If you have any questions about our data security architecture or wish to report a security inquiry, please contact our technical team directly: