Security at PDF Smart Kit
PDF Smart Kit is designed to reduce document exposure by processing supported files in the browser. This page explains what that means, what it does not guarantee and how to report a concern.
Browser-processing model
The current application reads selected files with browser JavaScript and WebAssembly components. Source document contents are not sent to a PDF Smart Kit application server for conversion. Temporary previews and results are held in browser memory for the active task.
The website still requests ordinary site assets and Google AdSense resources over the network. Those requests can expose standard connection and device information, but PDF Smart Kit does not intentionally attach the selected document contents to advertising requests.
Important boundaries
Local processing reduces server-side document exposure but does not make a compromised device, browser extension or browser session safe. Use an updated browser, avoid untrusted extensions, retain your own backup and inspect each result.
Password removal requires authorization. Visual signing does not verify identity. Redaction, conversion, OCR, repair and metadata operations have tool-specific limitations that are stated on their pages.
Responsible disclosure
Send a security report to help@pdfsk.com with the subject “PDF Smart Kit — Security”, or write to Windx Ltd at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Include affected URLs, reproducible steps, impact and a safe way to reproduce the issue.
Do not access data that is not yours, degrade availability, use social engineering, publish secrets or demand payment as a condition of withholding harmful activity. Windx Ltd will review good-faith reports and prioritize confirmed issues according to risk.
Security updates
Security information is reviewed when the processing architecture or a material dependency changes. Confirmed statements are corrected and the last-reviewed date is updated.