Privacy & Security
Specific, verifiable details about how documents are processed — not marketing claims. For the policy-level version, see the Privacy Policy.
Processing happens locally
Reading your PDF, rendering it on screen, detecting form fields, applying everything you type or draw, and generating the final downloaded file are all done by code running inside your browser tab. No document content is sent over the network at any point in that process.
Embedded scripts are never executed
Some PDFs contain embedded JavaScript (for example, to auto-calculate a field). This tool uses the PDF-rendering library only for reading and displaying pages and form field positions — it never loads the component that would execute a PDF's embedded scripts, so anything like that in a file you open simply doesn't run.
Filenames are sanitized
When your completed PDF is downloaded, its filename is built from your original file name with unsafe characters stripped out, rather than used as-is — this avoids a maliciously named file being able to affect how it's saved or displayed.
Nothing sensitive goes in a URL
Your document, form values and signatures are never placed into a URL, query string, or any other form of address — they only ever exist as in-memory data and local browser storage (see the Privacy Policy for what's stored and why).
What we don't claim
We won't describe this as “military-grade” or “bank-level” security, or claim a certification we don't hold. The measures above are the actual, specific things this tool does — that's a more useful basis for trust than a vague superlative.
Reporting a security issue
If you believe you've found a security issue, please email support@pdf-form-filler.example.com with details. We take these reports seriously and will follow up.