Your documents are yours. Our job is to process them safely, keep them private, and make sure the service is available when you need it. This page explains how we protect data across infrastructure, application code, people, and process.
Last updated: 31 October 2025
TLS 1.2+ in transit, AES‑256 at rest
Ephemeral processing: files auto‑delete by default
EU/UK hosting option; data locality respected
Role‑based access control; SSO/SAML available for Teams
Independent backups and disaster recovery
Vulnerability scanning and dependency patching
Responsible disclosure program
We enforceTLS 1.2+ for all connections toPDFHQ and our APIs. Documents stored at rest useAES‑256 encryption on encrypted volumes. Keys are managed by cloud‑native KMS with strict access policies and audit trails.
Links we generate for downloads and shares are time‑bound and include unguessable tokens. Expired links cannot be reused.
For most tools, files are processed in temporary storage and auto‑deletedshortly after completion. If you choose features like links, shared workspaces, or version history, we retain copies until you delete them or your policy dictates.
We store minimal operational metadata (file size, type, timestamps, processing status) to deliver features and troubleshoot issues. We do not sell or share your documents for advertising.
We operate on top of major cloud providers with physically secure data centers and certified controls (e.g., ISO 27001/27017/27018, SOC 1/2/3 — provider‑level). We use network segmentation, private subnets, WAF, and managed secrets.
EU/UK data residency is available for eligible workloads. Some telemetry (e.g., service health) may be processed globally but excludes document contents.
Internally, access followsRBAC andleast privilege. Production access is gated with MFA and audited. For customers, we provide role‑based permissions and, on Teams plans, optional SSO/SAML integration.
We maintain encrypted, point‑in‑time backups of critical configuration and account data. Operational runbooks cover disaster recovery and regional failover. We publish uptime on our Status page (coming soon) and design for graceful degradation of tools.
Signatures include tamper‑evident hashing and detailed audit trails (who, when, IP, user agent). Signed PDFs are sealed to prevent undetected changes. Optional signer authentication via email verification and two‑factor prompts is available for sensitive agreements.
When you opt into AI tools (summarize, translate, redact suggestions, etc.), content is processed by compute isolated from analytics and advertising. Unless you explicitly enable data sharing to improve models,your data is not used to train shared models.
We do not store raw card numbers. Payments are handled by PCI‑DSS compliant processors (e.g., Stripe). We store customer and subscription identifiers, not full card details.
We welcome reports from security researchers. If you believe you’ve found a vulnerability, contact us and we’ll investigate promptly. Please avoid accessing other users’ data and give us reasonable time to remediate before public disclosure.
/.well-known/security.txt.If you have compliance questionnaires or need a DPA, reach out to security@pdfhq.io. We’re happy to help.