Images
Product images, logos, and event and job images are uploaded in the Business Portal, checked as hostile until proven otherwise, and re-encoded from pixels before anything is stored where it can be served.
Uploading
Section titled “Uploading”- The portal asks for a signed upload policy for one image: its purpose, its type — JPEG, PNG or WebP — and its size, at most 10 MB. The image goes straight to private storage, never through the API, and the raw upload is never served.
- The person chooses a crop. One crop rectangle gives both shapes AI companies render: 1:1 and 1.91:1.
- The portal asks MasterDB to process the upload with that crop.
What processing does
Section titled “What processing does”- The type is read from the file’s own bytes, not its name or its declared type. SVG, XML, HTML and GIF are refused (
image_type_refused). - The dimensions are read before any pixel is decoded, so a decompression bomb is refused before it can do harm.
- The image is decoded in an isolated worker with pixel, memory and time limits (
image_invalidotherwise). - Every variant — the image itself, at most 2,048 pixels a side, and the two crops — is re-encoded from pixels, with all metadata stripped: no EXIF location, no XMP, no colour profiles, no text chunks.
- Each variant is stored under its own SHA-256 and served from MasterDB’s CDN, cacheable for a year; the URL goes into your draft. Processing the same upload again answers the same variants.
Images you host
Section titled “Images you host”A pushed product may name an image_url on your own site. It must be a safe URL — no private or local addresses — and like every URL you publish it is checked for malware and phishing at publish and daily afterwards; a flagged URL takes the row out of serving and opens a review.
What an image tells MasterDB
Section titled “What an image tells MasterDB”AI companies fetch images to render them, so image fetches are counted. They are a lower bound on renders, not an observation of every one.