Security program
Security & responsible disclosure.
Free PDF Conversion & Tools uses local-first processing and zero-knowledge encrypted storage while documenting controls that remain unverified.
Implemented controls
Controls include nonce-based Content Security Policy, background-worker PDF parsing, file and resource limits, authenticated encryption, strong generated passwords, two-phase one-view claims, route and link rate limits, migration-managed storage, verified deletion checks, privacy-safe operational counters, and short retention.
Zero-knowledge malware tradeoff
The server cannot scan encrypted content without breaking the promise that it cannot decrypt the file. The browser validates PDF signatures, but this is not a malware guarantee. Keep browsers updated and do not open untrusted output in privileged software.
Signing assurance
Signature requests record consent events, timestamps, pseudonymous actor records, document hashes, and a downloadable evidence record. The service does not independently verify identity, authority, delivery, custody, notarization, witnessing, or qualified-signature status.
Independent assurance status
No independent penetration test, cryptographic audit, SOC 2 examination, or external certification has been completed. These require qualified independent assessors.
Report a vulnerability
Email AkelasEnterprises@hotmail.com with [SECURITY] at the beginning of the subject. Do not include document contents, passwords, keys, personal information, or live exploit data.