How PDFVintage Protects Your Sensitive Documents
Security is built into every layer of PDFVintage. Discover how our client-side WebAssembly tools, isolated ephemeral cloud containers, and AES-256 encryption keep your files 100% private.
100% In-Browser Execution
21 of our 50+ tools (PDF Merging, Splitting, Compression, Rotation, Page operations, Watermarking, Signing, Image Conversion/Compression/Resizing/Cropping, and CSV/JSON/Images/Text-to-PDF generation) execute entirely inside your browser memory using WebAssembly & JS. Your files never leave your device.
Ephemeral Isolated Cloud Processing
Server-side tools (PDF-to-Word/Excel/CSV/PPT/HTML/Markdown/XML/EPUB, Office & e-book formats to PDF, Tabula table extraction, OCR, and PDF Protect/Unlock/Repair/Grayscale) execute in stateless, non-root isolated cloud containers. Files are processed in memory and purged instantly upon response stream completion.
AES-256 PDF Encryption
Protect sensitive documents with standard AES-256 encryption. Restrict printing, copying, and editing with dual owner/user passwords.
1. Dual Processing Engine Security Architecture
PDFVintage utilizes a modern dual-engine architecture designed to maximize privacy while delivering heavy desktop-grade conversion quality:
codeClient-Side WebAssembly Suite
Powered by modern WebAssembly and JavaScript engines. Operations like page reordering, page deletion, PDF splitting/merging, watermarking, rotation, and CSV/Text extraction run entirely on your CPU within browser memory boundaries. No server network calls are made.
cloud_queueServer-Side Ephemeral Containers
Powered by isolated microservices hosted on high-availability cloud infrastructure. Handles heavy conversions: PDF to Word/Excel/CSV/PPT/HTML/Markdown/XML/EPUB, Office and e-book formats to PDF (Word, Excel, PowerPoint, ODT, ODS, ODP, RTF, HTML, Markdown, EPUB, XML), Tabula table extraction, Optical Character Recognition (OCR), and PDF Protection/Unlock/Repair/Grayscale.
2. AI Resume & Document Parsing Privacy
Our AI Resume Builder and ATS Document Parser leverage advanced enterprise AI models under strict zero-data-retention terms:
- Strict In-Memory Schema Extraction: Document text is parsed directly into structured JSON structures (contact, experience, education, skills) and discarded immediately after response generation.
- Zero Model Training: Your documents, resume content, and bio text are never used to train, fine-tune, or improve public or private AI models.
- Zero Data Retention: Inputs are processed transiently in server memory without persistent storage or log logging of document payloads.
3. PDF Encryption, Password Protection & Repair
PDFVintage includes specialized PDF security tools engineered for strict cryptographic standards:
Applies AES-256 encryption with user & owner passwords. Restricts printing, copying, and modification per document policy.
Removes owner restrictions and passwords in-memory for authorized document owners without storing decryptions.
Sanitizes corrupted PDF streams, repairs cross-reference tables, and re-linearizes structure using native document engines.
4. Network & Infrastructure Hardening
Transport Layer Security (TLS 1.3): All network traffic between your browser and PDFVintage is enforced over HTTPS utilizing TLS 1.3 with modern AEAD cipher suites (AES-256-GCM / CHACHA20-POLY1305).
Same-Origin Proxy Architecture: Frontend browser requests route through our same-origin proxy (/api/proxy/convert). Backend conversion endpoints are isolated from direct browser CORS exposure.
Container Isolation & Resource Quotas: Conversion containers execute in isolated Linux sandboxes with strict non-root execution policies, high-memory caps per instance, and automatic lifecycle teardown.
Firebase Authentication & Short-Lived Tokens: Accounts are handled by Google Firebase Authentication. Sessions use short-lived ID tokens (~1 hour) that the server verifies against Google's public keys on every privileged request — there are no long-lived server sessions to steal.
Google Cloud Run Infrastructure: All server-side processing runs on Google Cloud Run (us-central1) across three specialized engines — the office-conversion service (LibreOffice), the Tabula table-extraction service, and the Docling AI OCR service — each an isolated, autoscaled container with zero file persistence.
5. Global Regulatory Compliance (GDPR & CCPA)
PDFVintage complies with European Union General Data Protection Regulation (GDPR) Article 25 (Data protection by design and by default) and Article 32 (Security of processing), as well as the California Consumer Privacy Act (CCPA):
- No Data Sale or Monetization: We do not profile users, sell metadata, or monetize document contents.
- Data Minimization: Only necessary document bytes are held transiently in RAM during active conversion tasks.
- Right to Erasure: Files are automatically deleted from RAM immediately after stream delivery.
Security Specifications at a Glance
| Security Vector | PDFVintage Implementation | User Benefit |
|---|---|---|
| Client Tools Execution | 100% In-Browser WebAssembly & JS Engines | Files never touch the internet |
| Server Tools Execution | Ephemeral Isolated Cloud Containers (RAM-only) | Wiped immediately upon completion |
| Data Retention | Zero-retention policy + 5-min container purge failsafe | No residual files stored anywhere |
| AI Privacy | Enterprise AI Engine in structured JSON mode | Zero model training or data logging |
| Transport Encryption | TLS 1.3 with AES-256-GCM / CHACHA20-POLY1305 | Protected against network eavesdropping |
| PDF Cryptography | AES-256 Protect/Unlock/Repair engines | Industry-standard document locking |
Have Security or Compliance Questions?
Our security team is dedicated to maintaining the highest standard of data privacy. For security inquiries, vulnerability disclosures, or enterprise security questionnaires, contact us.