PDFArrow · Trust center

Current security controls, product boundaries, and reporting path

Security documentation should distinguish implemented controls from aspirations. This page does not claim an external audit, certification, or compliance program that has not been completed.

Reviewed July 21, 2026 by PDFArrow Product Engineering.

Browser boundary

Supported core PDF work runs locally, reducing document transfer. Browser-only processing is not the same as end-to-end encryption, a sandbox guarantee, or a formal compliance certification.

Identity and access

Firebase Authentication supports email and Google sign-in. Private app routes require authentication, document records are scoped to their owner, and the analytics dashboard checks the configured owner identity.

Passwords and sensitive values

PDF passwords are used in browser memory for the requested operation and are not included in product analytics. PDFArrow cannot recover a password it does not store.

Dependencies and releases

The product uses pinned application dependencies, automated unit and browser regression suites, route audits, and a core quality gate before release. This reduces risk but cannot prove the absence of vulnerabilities.

Report a security issue

Use Support and choose Security. Include the affected route, impact, reproduction steps, and a safe test file if needed. Do not send real credentials, secrets, or another person's confidential PDF.

Related tools and resources