Trust & security
We take the security of SecurePDF AI seriously. This page is the authoritative reference for the Policy entry in our security.txt file and explains how to report a vulnerability, what is in scope, and the protections we extend to good-faith researchers.
Last updated: 2026-05-17
Files are encrypted with AES-256-GCM the moment they touch our storage. Keys are isolated per job.
TLS 1.2+ on every endpoint, HSTS preloaded, and strict transport security enforced site-wide.
Uploads are encrypted at rest and purged at the end of your tier’s download window (1 hour on Free, 24 hours on Pro / Teams). Files are never mined or used to train models.
Every conversion runs in an ephemeral worker. Cross-job state is impossible by design.
We are working toward SOC 2 Type II readiness. Audit timeline and report channel published when ready.
Free-tier tools work without sign-up. We cannot leak data we never asked for.
Security is the foundation of SecurePDF AI — not a feature. We operate a no-account service that encrypts every upload at rest and purges it at the end of your tier’s download window. We recognize the responsibility that comes with handling other people's files. We are committed to:
If you believe you have discovered a security issue affecting SecurePDF AI, please report it via one of the channels below. We prefer encrypted email for sensitive details.
To help us triage quickly, please include:
Please do not disclose the issue publicly, to third parties, or via social media until we have had a reasonable opportunity to investigate and remediate (see Response Timelines).
Reports against the following assets are in scope and eligible for coordinated disclosure under this policy:
securepdfai.com and its API endpoints.securepdfai.com (including the blog, legal pages, and comparison content).sw.js, manifest.json, and related offline functionality.The following are out of scope, even if they appear to affect SecurePDF AI users:
SecurePDF AI supports good-faith security research. If you make a good-faith effort to comply with this policy during your research, we will:
To stay within safe harbor, please do not:
If in doubt about whether an action falls within safe harbor, email [email protected] before proceeding.
We aim to handle every report on the following schedule. These are targets, not contractual commitments — complex issues may take longer, and we will keep you informed if they do.
We publicly recognize researchers who have responsibly disclosed vulnerabilities to us. With your permission, we will list your name, handle, or organization here.
To be announced. The Hall of Fame will be populated as valid reports are received and remediated.
We do not currently run a paid bug bounty program. Recognition for valid, responsibly disclosed reports is published in the Hall of Fame. We are evaluating structured rewards for the next phase — if you would like to coordinate a private disclosure ahead of that, please reach out at [email protected].
For sensitive reports, please encrypt your message using our PGP key. The authoritative copy will be published at /.well-known/pgp-key.txt and referenced from our security.txt.
PGP key fingerprint to be announced. Until the key is published, please use TLS-encrypted email or the web report form for sensitive details, and avoid attaching exploit payloads.
For all security-related correspondence: [email protected]. For general inquiries, use [email protected].