Security
How we protect your documents and your account.
ChangeMyPDF is built for environments where document confidentiality is non-negotiable — legal, finance, healthcare, and operations. Security is a product feature, not a checkbox.
Encryption at every layer
TLS 1.3 in transit, AES-256-GCM at rest. KMS-managed keys with annual rotation.
Sandboxed processing
Workers run under gVisor with strict syscall filters and a read-only rootfs.
AV scanning
Every upload is scanned with ClamAV before any tool touches it.
Auto-delete by default
Free: 1h. Premium: 7d. Business+: configurable, including "never store".
Data residency
Enterprise customers can pin their data to EU or US regions.
SSO + 2FA
SAML and OIDC for enterprise. TOTP-based 2FA for everyone, free of charge.
Compliance
ChangeMyPDF is on track for SOC 2 Type II by Q3. GDPR and CCPA compliant. We sign Data Processing Agreements (DPAs) with Business and Enterprise customers on request.
Responsible disclosure
Found a vulnerability? Email security@changemypdf.com. We'll respond within 24 hours and aim to resolve verified issues within 90 days. We run a bug bounty program for production-impact vulnerabilities.