Trust
Security
We process documents that often contain confidential information. Treating that responsibly is the entire premise of the product.
Privacy by default
321 of our 629 tools execute entirely in your browser via WebAssembly — those files are never uploaded, and each tool page says so before you pick a file. The remaining 308 need a server; those files are deleted an hour after upload if you are not signed in, and 24 hours if you are. Plan makes no difference — a free account gets the same 24 hours as a paid one.
Encryption
Files at rest are protected with envelope encryption: each file gets a fresh AES-256-GCM data key, wrapped with a per-tenant key derived from a master key held in our secret manager. TLS 1.3 in transit, HSTS preload, strict CSP with nonces.
No third-party processing
We don't ship your bytes to OpenAI, Google, or any other vendor. OCR, AI transcription, background removal, and upscaling all run on infrastructure we operate.
Authentication
Email + password (Argon2id), passkeys (WebAuthn), Google / GitHub / Microsoft OAuth, and email magic links. SAML SSO + SCIM provisioning available on Enterprise.
Audit log
Business and Enterprise plans include a tamper-evident audit log of every privileged action (member changes, key issuance, billing changes).
Compliance
SOC 2 Type II in progress. GDPR DSR endpoint for data exports & deletion. DPA + SCCs available on request.
Reporting a vulnerability
Email [email protected] (see security.txt). We aim to acknowledge within 24h. We run a private bounty programme on HackerOne — ask to be added.