Skip to content
Folio

Security

Browser-local processing reduces the amount of sensitive document data that needs to leave your device.

Last updated: 2026-09-08

Architecture

  • Browser tools process selected files entirely in the current tab.
  • There is no document API, upload endpoint or document database.
  • No remote conversion API, analytics SDK or advertising tracker is used by Folio.
  • PDF rendering and conversion dependencies are served with the application.

Browser boundaries

  • Files are read only after you select or drop them into a tool.
  • Results are created as browser downloads and are not retained by Folio.
  • File size limits and input validation reduce accidental resource exhaustion.
  • Folio does not execute document content as code or expose a server-side conversion fallback.

Responsible disclosure

Do not include real document contents in a report or publicly disclose an unpatched vulnerability. Include the affected component, version or commit, reproduction steps and impact. See SECURITY.md for the process and scope.

Security contact: ekaitzrockandroll@gmail.com

These measures reduce risk but are not a guarantee of absolute security. Keep your browser and operating system up to date.