Security at PDFLeo
PDFLeo aims to handle documents responsibly and to be transparent about the limits of its current setup.
Browser-based processing
Tools designed for local processing work in your browser rather than intentionally sending selected documents to a PDFLeo file-processing server. Third-party libraries may be loaded by your browser. Feature behavior can differ, so avoid using a tool for highly confidential files unless you understand how that feature works.
Connection security
Use the HTTPS version of the website when a valid certificate is active. The custom-domain certificate and HTTPS enforcement must be confirmed in GitHub Pages settings before PDFLeo claims that its custom domain is secured by HTTPS. Do not enter passwords or sensitive information on a page that shows a browser security warning.
Accounts
The website includes a Supabase-based sign-up, login and password-recovery interface. Email delivery depends on the project's SMTP/domain configuration and must be tested end to end before being relied upon. Keep redirect URLs restricted to legitimate PDFLeo domains, enforce appropriate database row-level security, and never put private service-role credentials in public client-side code.
Certifications and affiliations
PDFLeo does not claim ISO/IEC 27001 certification or PDF Association membership unless and until the relevant certification or membership has actually been granted and is current. Security badges must not be interpreted as a substitute for checking the actual configuration and practices.
Report a security concern
Please report suspected vulnerabilities responsibly and avoid accessing, changing, or downloading other people's information. Contact: hello@pdfleo.online. This mailbox must be configured and monitored before it is relied on.