Security
There is no server to attack
FileSlimmer deploys as static files. There is no application server, no database, no edge function and no public API, so the classes of vulnerability that need one — SQL injection, server-side request forgery, authentication bypass, insecure direct object references — have no surface here. The build fails if a server artifact appears in the output at all.
Response headers
Content-Security-Policywithdefault-src 'self'andconnect-src 'self': even if code attempted an outbound request, the browser would refuse it.object-src 'none',base-uri 'none'andframe-ancestors 'none'.X-Content-Type-Options: nosniffandX-Frame-Options: DENY.Referrer-Policy: no-referrer, so a page address never travels with an outbound navigation.Cross-Origin-Resource-Policy: same-origin, and a restrictivePermissions-Policy.- The video and AI routes additionally carry the cross-origin isolation headers those APIs require.
A build-time check asserts each of these against the deployed artifact, and a connect-src that permitted anything beyond the same origin fails the build.
Your files are treated as untrusted input
- File type is decided by magic bytes, never by the extension or by the MIME type the operating system attaches — both are attacker-controlled for a dropped file.
- SVG, JavaScript, CSS and HTML are parsed and rewritten as text and are never executed. An SVG preview is sanitized first — scripts, event handlers and external references removed — and rendered in a sandboxed frame, never injected into this page.
- External
@importURLs in a stylesheet are not fetched. - Decompression-bomb budgets cap file size and element counts, and a decoded-to-stored ratio above the threshold asks for explicit confirmation before the work starts.
- An encrypted PDF is never opened by ignoring its encryption. Structural tools are disabled for it, and the rasterizing path runs only with a password you supply, held in memory, after an explicit warning about what rasterizing destroys.
Third-party code
Every library, WebAssembly module, font and AI model is served from this domain. No content delivery network is in the request path, so a compromise of a third-party host cannot reach this site. Component versions are pinned, and each one is listed with its licence and source repository on the open-source page. AI model files are pinned by hash and refused if the hash does not match.
What this page does not claim
None of the above is a statement about your device. A browser extension can read page contents, your operating system can inspect any file you open, and security software on your machine sits between the two. Those are outside any website's control; the privacy statement says the same thing about data.
Reporting a vulnerability
Write to info@zenitgroup.com.co with the affected URL, the browser and version, and the steps to reproduce. Please do not run denial-of-service or automated scanning traffic against the site: the hosting is shared with everyone else using it. There is no bug-bounty programme; reports are read and answered by the operator named at the foot of this page.
This document is published by ZENIT GROUP S.A.S., Cali, Valle del Cauca, Colombia.