Skip to content

Security

Last updated October 2026

People trust us with contracts, IDs and financial records. These are the controls that protect them.

Local-first architecture

Editing, signing, annotating, organising, watermarking, compression and image conversion run in your browser. The safest upload is the one that never happens.

Cloud processing controls

  • TLS for all traffic; HSTS preloaded.
  • Private storage only reachable through signed URLs that expire after 15 minutes.
  • Content-based file type validation. The file extension is never trusted.
  • Per-file size limits and per-client rate limits.
  • Processing in non-root, resource-limited containers with no outbound internet access and a strict time limit per job.
  • Pluggable malware scanning before processing.
  • Automatic deletion after 60 minutes, with a 24-hour storage lifecycle backstop.

Web application

  • Strict Content Security Policy, frame-ancestors none, no third-party scripts in the editor.
  • Hyperlinks added to PDFs are limited to http(s) and mailto, never JavaScript.
  • True redaction: redacted content is removed from the output file, not only covered.

Reporting a vulnerability

Please email support@pdfella.example. We respond within two business days.