ChangeMyPDF

Security

How we protect your documents and your account.

ChangeMyPDF is built for environments where document confidentiality is non-negotiable — legal, finance, healthcare, and operations. Security is a product feature, not a checkbox.

Encryption at every layer

TLS 1.3 in transit, AES-256-GCM at rest. KMS-managed keys with annual rotation.

Sandboxed processing

Workers run under gVisor with strict syscall filters and a read-only rootfs.

AV scanning

Every upload is scanned with ClamAV before any tool touches it.

Auto-delete by default

Free: 1h. Premium: 7d. Business+: configurable, including "never store".

Data residency

Enterprise customers can pin their data to EU or US regions.

SSO + 2FA

SAML and OIDC for enterprise. TOTP-based 2FA for everyone, free of charge.

Compliance

ChangeMyPDF is on track for SOC 2 Type II by Q3. GDPR and CCPA compliant. We sign Data Processing Agreements (DPAs) with Business and Enterprise customers on request.

Responsible disclosure

Found a vulnerability? Email security@changemypdf.com. We'll respond within 24 hours and aim to resolve verified issues within 90 days. We run a bug bounty program for production-impact vulnerabilities.