Security
PDF Pouch reduces document exposure by processing selected files locally. That is a useful control, but it does not make arbitrary files risk-free.
Controls in this release
- Production dependencies and OCR assets are version-pinned, bundled, and served from the PDF Pouch origin.
- A restrictive Content Security Policy blocks third-party scripts, framing, plugins, and unexpected network destinations.
- PDF.js evaluation support is disabled when opening documents.
- File size, selection, page count, image dimension, and canvas allocation limits reduce resource-exhaustion risk.
- The production deployment publishes only generated files from the
distdirectory.
Your responsibility
Keep your browser updated, retain the original document until you verify the output, and do not use the unlock tool unless you own the document or have permission to modify it. Highly sensitive environments should use reviewed offline software and organisational controls appropriate to their risk.
Report a vulnerability
Email security@pdfpouch.com. Please do not include confidential documents in a report.