Skip to content

Security

Last updated: August 22, 2026

This page describes security controls currently implemented for pdfs.build. It does not claim a certification or guarantee that every security event can be prevented.

Transport and browser controls

  • Public application and website traffic is served over HTTPS.
  • The application and website configure HSTS, content-type protection, referrer and permissions policies, and framing restrictions.
  • The application's Content Security Policy is currently deployed in report-only mode while compatibility is validated.

Accounts and access

  • Passwords are stored as one-way hashes rather than plaintext.
  • Authenticated browser sessions use HTTP-only cookies with production security attributes.
  • Google and GitHub OAuth are optional sign-in methods.
  • Organizations, workspaces, API keys, and public links have separate authorization checks and scopes.
  • API keys are shown only when created and stored as hashes.

Application and data handling

  • Application services run in containers; PostgreSQL and Redis are operated as managed-by-us service components on our hosting environment.
  • Uploads and generated assets are stored in Cloudflare R2, with access mediated through configured application and delivery URLs.
  • Deployment credentials and provider keys are supplied through the production environment rather than committed to the repository.
  • When Sentry monitoring is enabled, our application configuration disables default PII collection; browser session replay is disabled.
  • Payment-card entry and processing are handled by Polar and its payment providers. pdfs.build receives billing and entitlement metadata, not full card numbers.

AI processing

AI requests are sent only when an AI feature is used and can include the content required to perform the request. Current providers, purposes, and processing locations are listed on ourSubprocessor List. Customers should not place sensitive or regulated data in AI requests unless their organization has approved the applicable feature.

Customer responsibilities

Customers are responsible for:

  • using unique credentials and multi-factor authentication on connected identity-provider accounts;
  • reviewing organization membership, API keys, embeds, forms, and public links;
  • limiting submitted data to what is necessary and choosing appropriate features and providers;
  • validating generated documents and AI output before use; and
  • promptly reporting suspected account compromise or security issues.

Vulnerability disclosure

Report suspected vulnerabilities privately to[email protected] with a description, impact, reproduction steps, and relevant logs or screenshots. Do not access other users' data, disrupt the Service, use social engineering, or disclose an issue publicly before we have had a reasonable opportunity to investigate. We do not currently operate a paid bug bounty.

Assurance

We do not currently claim SOC 2, ISO 27001, or an independent penetration-test certification. Enterprise customers may contact us for a current security questionnaire or to discuss additional contractual requirements.

Contact

Security reports and due-diligence questions:[email protected].