Security policy
The safest place for your document is your own device, so that is where it stays. Here is how the site is built to protect you.
Your files never leave your device
Every tool works on your device, inside your browser. There is no upload step, no storage of documents on our side and nothing to delete afterwards, so there is no copy of your files that could be exposed in a breach. The site does not accept uploads at all: anything other than a request for a page is refused.
A strict security policy on every page
Every page is sent with a content security policy that your browser enforces. The part of the site that handles your files may connect only to this site, may load nothing from anywhere else, and may send nothing anywhere at all. Pages that show advertising carry a separate policy that permits the advertising service and nothing besides.
Everything served from this site
The pages, the styles, the typeface and the tools are all delivered from this site itself. Nothing is loaded from other content networks or font services. Advertising is the one thing that comes from elsewhere, and it is kept apart from the part of the site that handles your files.
Every result is checked
Before a tool offers you a file, it opens what it made and checks it against what you asked for. If a check fails, nothing is offered and your original is untouched.
Strong protection for locked documents
Protect PDF encrypts documents with AES-256, the strongest encryption the PDF format supports, and confirms the result with a second, independent PDF reader. Passwords are used on your device and never sent or stored.
Hosting
The site is hosted on Cloudflare's network, which serves it over encrypted HTTPS connections. Cloudflare publishes the security certifications it holds for its own platform on its Trust Hub. Those certifications describe Cloudflare's infrastructure; NoUploadPDF itself holds no security certification.
Reporting a security issue
If you believe you have found a security problem, please email nouploadpdf@gmail.com with "Security" in the subject line. Include a description of the issue, the steps to reproduce it and its likely impact. We will acknowledge your report, keep you informed, and ask that you allow a reasonable time for a fix before sharing details publicly. Please do not test in a way that could harm other visitors or the availability of the site.