Security
Last updated October 2026
People trust us with contracts, IDs and financial records. These are the controls that protect them.
Local-first architecture
Editing, signing, annotating, organising, watermarking, compression and image conversion run in your browser. The safest upload is the one that never happens.
Cloud processing controls
- TLS for all traffic; HSTS preloaded.
- Private storage only reachable through signed URLs that expire after 15 minutes.
- Content-based file type validation. The file extension is never trusted.
- Per-file size limits and per-client rate limits.
- Processing in non-root, resource-limited containers with no outbound internet access and a strict time limit per job.
- Pluggable malware scanning before processing.
- Automatic deletion after 60 minutes, with a 24-hour storage lifecycle backstop.
Web application
- Strict Content Security Policy, frame-ancestors none, no third-party scripts in the editor.
- Hyperlinks added to PDFs are limited to http(s) and mailto, never JavaScript.
- True redaction: redacted content is removed from the output file, not only covered.
Reporting a vulnerability
Please email support@pdfella.example. We respond within two business days.