PDFHQ logo
Security & Trust

Security at PDFHQ

Your documents are yours. Our job is to process them safely, keep them private, and make sure the service is available when you need it. This page explains how we protect data across infrastructure, application code, people, and process.

Last updated: 31 October 2025

At a glance

  • TLS 1.2+ in transit, AES‑256 at rest

  • Ephemeral processing: files auto‑delete by default

  • EU/UK hosting option; data locality respected

  • Role‑based access control; SSO/SAML available for Teams

  • Independent backups and disaster recovery

  • Vulnerability scanning and dependency patching

  • Responsible disclosure program

Contents

  • Encryption
  • File handling & retention
  • Infrastructure & data centers
  • Application security
  • Access control
  • Backups & availability
  • Compliance & privacy
  • E‑signing security
  • AI features & privacy
  • Payments & billing
  • Responsible disclosure
  • Contact our security team

Encryption

We enforceTLS 1.2+ for all connections toPDFHQ and our APIs. Documents stored at rest useAES‑256 encryption on encrypted volumes. Keys are managed by cloud‑native KMS with strict access policies and audit trails.

Links we generate for downloads and shares are time‑bound and include unguessable tokens. Expired links cannot be reused.

File handling & retention

Infrastructure & data centers

We operate on top of major cloud providers with physically secure data centers and certified controls (e.g., ISO 27001/27017/27018, SOC 1/2/3 — provider‑level). We use network segmentation, private subnets, WAF, and managed secrets.

EU/UK data residency is available for eligible workloads. Some telemetry (e.g., service health) may be processed globally but excludes document contents.

Application security

  • Secure SDLC: code review, CI checks, and automated dependency scanning.
  • Secrets hygiene: short‑lived credentials, KMS‑managed keys, no secrets in code.
  • Isolation: per‑request containers/functions where possible; least privilege IAM.
  • Monitoring: centralized logs, anomaly alerts, and rate‑limiting.

Access control

Internally, access followsRBAC andleast privilege. Production access is gated with MFA and audited. For customers, we provide role‑based permissions and, on Teams plans, optional SSO/SAML integration.

Backups & availability

We maintain encrypted, point‑in‑time backups of critical configuration and account data. Operational runbooks cover disaster recovery and regional failover. We publish uptime on our Status page (coming soon) and design for graceful degradation of tools.

Compliance & privacy

  • GDPR/UK GDPR: we act asprocessor for documents you upload. A DPA is available for Teams customers upon request.
  • Sub‑processors: limited, vetted providers required to deliver the service.
  • Privacy by design: we minimize personal data collection and provide export/delete controls.

E‑signing security

Signatures include tamper‑evident hashing and detailed audit trails (who, when, IP, user agent). Signed PDFs are sealed to prevent undetected changes. Optional signer authentication via email verification and two‑factor prompts is available for sensitive agreements.

AI features & privacy

When you opt into AI tools (summarize, translate, redact suggestions, etc.), content is processed by compute isolated from analytics and advertising. Unless you explicitly enable data sharing to improve models,your data is not used to train shared models.

Payments & billing

We do not store raw card numbers. Payments are handled by PCI‑DSS compliant processors (e.g., Stripe). We store customer and subscription identifiers, not full card details.

Responsible disclosure

We welcome reports from security researchers. If you believe you’ve found a vulnerability, contact us and we’ll investigate promptly. Please avoid accessing other users’ data and give us reasonable time to remediate before public disclosure.

  • Email: security@pdfhq.io
  • PGP: Coming soon — we’ll publish a public key and security.txt at/.well-known/security.txt.

Questions?

If you have compliance questionnaires or need a DPA, reach out to security@pdfhq.io. We’re happy to help.