verified_userEnterprise-Grade Security & Zero-Retention Architecture

How PDFVintage Protects Your Sensitive Documents

Security is built into every layer of PDFVintage. Discover how our client-side WebAssembly tools, isolated ephemeral cloud containers, and AES-256 encryption keep your files 100% private.

laptop_mac

100% In-Browser Execution

21 of our 50+ tools (PDF Merging, Splitting, Compression, Rotation, Page operations, Watermarking, Signing, Image Conversion/Compression/Resizing/Cropping, and CSV/JSON/Images/Text-to-PDF generation) execute entirely inside your browser memory using WebAssembly & JS. Your files never leave your device.

cloud_sync

Ephemeral Isolated Cloud Processing

Server-side tools (PDF-to-Word/Excel/CSV/PPT/HTML/Markdown/XML/EPUB, Office & e-book formats to PDF, Tabula table extraction, OCR, and PDF Protect/Unlock/Repair/Grayscale) execute in stateless, non-root isolated cloud containers. Files are processed in memory and purged instantly upon response stream completion.

lock

AES-256 PDF Encryption

Protect sensitive documents with standard AES-256 encryption. Restrict printing, copying, and editing with dual owner/user passwords.

memory

1. Dual Processing Engine Security Architecture

PDFVintage utilizes a modern dual-engine architecture designed to maximize privacy while delivering heavy desktop-grade conversion quality:

codeClient-Side WebAssembly Suite

Powered by modern WebAssembly and JavaScript engines. Operations like page reordering, page deletion, PDF splitting/merging, watermarking, rotation, and CSV/Text extraction run entirely on your CPU within browser memory boundaries. No server network calls are made.

cloud_queueServer-Side Ephemeral Containers

Powered by isolated microservices hosted on high-availability cloud infrastructure. Handles heavy conversions: PDF to Word/Excel/CSV/PPT/HTML/Markdown/XML/EPUB, Office and e-book formats to PDF (Word, Excel, PowerPoint, ODT, ODS, ODP, RTF, HTML, Markdown, EPUB, XML), Tabula table extraction, Optical Character Recognition (OCR), and PDF Protection/Unlock/Repair/Grayscale.

auto_awesome

2. AI Resume & Document Parsing Privacy

Our AI Resume Builder and ATS Document Parser leverage advanced enterprise AI models under strict zero-data-retention terms:

  • Strict In-Memory Schema Extraction: Document text is parsed directly into structured JSON structures (contact, experience, education, skills) and discarded immediately after response generation.
  • Zero Model Training: Your documents, resume content, and bio text are never used to train, fine-tune, or improve public or private AI models.
  • Zero Data Retention: Inputs are processed transiently in server memory without persistent storage or log logging of document payloads.
shield_lock

3. PDF Encryption, Password Protection & Repair

PDFVintage includes specialized PDF security tools engineered for strict cryptographic standards:

Protect PDF

Applies AES-256 encryption with user & owner passwords. Restricts printing, copying, and modification per document policy.

Unlock PDF

Removes owner restrictions and passwords in-memory for authorized document owners without storing decryptions.

Repair PDF

Sanitizes corrupted PDF streams, repairs cross-reference tables, and re-linearizes structure using native document engines.

network_ping

4. Network & Infrastructure Hardening

Transport Layer Security (TLS 1.3): All network traffic between your browser and PDFVintage is enforced over HTTPS utilizing TLS 1.3 with modern AEAD cipher suites (AES-256-GCM / CHACHA20-POLY1305).

Same-Origin Proxy Architecture: Frontend browser requests route through our same-origin proxy (/api/proxy/convert). Backend conversion endpoints are isolated from direct browser CORS exposure.

Container Isolation & Resource Quotas: Conversion containers execute in isolated Linux sandboxes with strict non-root execution policies, high-memory caps per instance, and automatic lifecycle teardown.

Firebase Authentication & Short-Lived Tokens: Accounts are handled by Google Firebase Authentication. Sessions use short-lived ID tokens (~1 hour) that the server verifies against Google's public keys on every privileged request — there are no long-lived server sessions to steal.

Google Cloud Run Infrastructure: All server-side processing runs on Google Cloud Run (us-central1) across three specialized engines — the office-conversion service (LibreOffice), the Tabula table-extraction service, and the Docling AI OCR service — each an isolated, autoscaled container with zero file persistence.

gavel

5. Global Regulatory Compliance (GDPR & CCPA)

PDFVintage complies with European Union General Data Protection Regulation (GDPR) Article 25 (Data protection by design and by default) and Article 32 (Security of processing), as well as the California Consumer Privacy Act (CCPA):

  • No Data Sale or Monetization: We do not profile users, sell metadata, or monetize document contents.
  • Data Minimization: Only necessary document bytes are held transiently in RAM during active conversion tasks.
  • Right to Erasure: Files are automatically deleted from RAM immediately after stream delivery.

Security Specifications at a Glance

Security VectorPDFVintage ImplementationUser Benefit
Client Tools Execution100% In-Browser WebAssembly & JS EnginesFiles never touch the internet
Server Tools ExecutionEphemeral Isolated Cloud Containers (RAM-only)Wiped immediately upon completion
Data RetentionZero-retention policy + 5-min container purge failsafeNo residual files stored anywhere
AI PrivacyEnterprise AI Engine in structured JSON modeZero model training or data logging
Transport EncryptionTLS 1.3 with AES-256-GCM / CHACHA20-POLY1305Protected against network eavesdropping
PDF CryptographyAES-256 Protect/Unlock/Repair enginesIndustry-standard document locking

Have Security or Compliance Questions?

Our security team is dedicated to maintaining the highest standard of data privacy. For security inquiries, vulnerability disclosures, or enterprise security questionnaires, contact us.