Security
Browser-local processing reduces the amount of sensitive document data that needs to leave your device.
Last updated: 2026-09-08
Architecture
- Browser tools process selected files entirely in the current tab.
- There is no document API, upload endpoint or document database.
- No remote conversion API, analytics SDK or advertising tracker is used by Folio.
- PDF rendering and conversion dependencies are served with the application.
Browser boundaries
- Files are read only after you select or drop them into a tool.
- Results are created as browser downloads and are not retained by Folio.
- File size limits and input validation reduce accidental resource exhaustion.
- Folio does not execute document content as code or expose a server-side conversion fallback.
Responsible disclosure
Do not include real document contents in a report or publicly disclose an unpatched vulnerability. Include the affected component, version or commit, reproduction steps and impact. See SECURITY.md for the process and scope.
Security contact: ekaitzrockandroll@gmail.com
These measures reduce risk but are not a guarantee of absolute security. Keep your browser and operating system up to date.