PFree PDF Tools
Local-first

Security program

Security & responsible disclosure.

Free PDF Conversion & Tools uses local-first processing and zero-knowledge encrypted storage while documenting controls that remain unverified.

Implemented controls

Controls include nonce-based Content Security Policy, background-worker PDF parsing, file and resource limits, authenticated encryption, strong generated passwords, two-phase one-view claims, route and link rate limits, migration-managed storage, verified deletion checks, privacy-safe operational counters, and short retention.

Zero-knowledge malware tradeoff

The server cannot scan encrypted content without breaking the promise that it cannot decrypt the file. The browser validates PDF signatures, but this is not a malware guarantee. Keep browsers updated and do not open untrusted output in privileged software.

Signing assurance

Signature requests record consent events, timestamps, pseudonymous actor records, document hashes, and a downloadable evidence record. The service does not independently verify identity, authority, delivery, custody, notarization, witnessing, or qualified-signature status.

Independent assurance status

No independent penetration test, cryptographic audit, SOC 2 examination, or external certification has been completed. These require qualified independent assessors.

Report a vulnerability

Email AkelasEnterprises@hotmail.com with [SECURITY] at the beginning of the subject. Do not include document contents, passwords, keys, personal information, or live exploit data.