Our approach
Security statements should describe what the product actually does. Convert2PDF does not claim certifications, independent audits, end-to-end encryption or perfect security that have not been verified.
Local processing for current tools
All currently configured document tools use client-side processing. Selected file bytes are read by JavaScript libraries in the browser and results are created as local Blob objects. The application has no document upload or temporary-file route for these tools.
This design reduces exposure to a document-processing server, but it does not control browser extensions, device security or other software on a user's computer.
Web application safeguards
The current PHP application implements:
- a restrictive Content Security Policy for scripts, images, workers, connections and framing;
- frame denial, MIME-sniffing protection and a strict-origin referrer policy;
- native prepared database statements;
- authenticated administrative sessions, CSRF validation for admin changes and secure cookie attributes in production;
- validation of supported MIME types, file sizes, total sizes, file counts and PDF page counts in the browser;
- event tracking that excludes filenames, document text, Blob URLs and file bytes;
- user-facing error handling without intentionally transmitting document contents.
HTTPS
The application is designed to be served over HTTPS, but TLS certificates and redirects are controlled by the production web server or hosting platform rather than this repository. HTTPS must be verified on the deployed domain before launch.
Server processing and storage
There is no server-side document processor in the current application. Consequently, the application does not create temporary server copies of files selected in the current tools. If that architecture changes, the affected tool, storage location, access controls and deletion schedule must be documented before release.
Limits of this information
Hosting-provider controls, infrastructure patching, backups, log retention, incident response procedures and production monitoring are not documented in the repository and require confirmation from the owner or hosting administrator.
Reporting a vulnerability
Please send a clear description and reproduction steps to [email protected]. Do not include sensitive documents or exploit other users' data. We do not promise a specific response time until a formal security-response process is established.
See also Your Files, Your Privacy and the Privacy Policy.