Security
What we actually do to keep your documents safe — and nothing we don’t.
Processing on your device
Most tools run in your browser, so the file never reaches our servers at all. Heavy work runs in a background Web Worker so pages stay responsive.
Encryption in transit
All traffic uses HTTPS (the production deployment enforces HSTS). Files are never sent over plain HTTP.
Temporary, isolated processing
- Each upload gets a random 128-bit job ID and a separate 256-bit access token; only a hash of the token is stored.
- Files are checked against an allow-list of extensions and their actual content (magic bytes), not just the name.
- Conversion engines run as separate processes with a fixed program allow-list, without a shell, with time and memory limits, inside containers that run as non-root with a read-only filesystem and dropped privileges.
- Every PDF we produce is checked for structural integrity before you can download it.
- Inputs are deleted when processing finishes; results within 30 minutes, or immediately when you click “Delete now”. A cleanup process sweeps storage every minute, independent of application shutdown.
- Downloaded HTML and SVG results are served with a sandboxing Content-Security-Policy so they can’t run in our site’s context.
Web page conversion
URL to PDF only visits public addresses. Every request the renderer makes — including redirects and embedded resources — is checked against private, loopback, link-local and cloud-metadata address ranges. Pasted HTML is rendered with JavaScript and network access disabled.
Abuse protection
Rate limits, per-user concurrent job limits and queue limits protect the free service. They apply equally to everyone and are never used to sell upgrades.
Real redaction
Redact PDF rebuilds affected pages as images with the redactions burned in, removes document metadata, and verifies that no text remains before offering the file. The separate “whiteout” tool in the editor only covers content and says so.
What we don’t do
- We don’t sell documents or data, and we don’t use your files to train AI.
- We don’t crack passwords.
- Admin tools show only aggregate numbers — never file names or contents.
Reporting a vulnerability
Please email security@example.com with details and steps to reproduce. We aim to respond within a few days and are happy to credit responsible reporters. You can also use the contact page.