Security Data handling and retention
What happens to what you send.
Every render runs isolated, with no credentials and no route to private infrastructure. Here is exactly what is stored, what is not, and for how long.
01Render isolation
Each PDF render runs in an isolated, sandboxed environment with no credentials attached and no route to private infrastructure. Outbound requests from rendered pages are validated against public IP ranges before being allowed. Requests to private RFC-1918 address space, loopback, and link-local ranges are blocked at the network layer.
sandboxed per renderno private network accesspublic IP validation02Data we store
We store the minimum required to operate the service.
- API keys: hashed. The plaintext key is shown once at creation and never stored afterward.
- Usage counts: a per-billing-period counter to enforce plan limits.
- Stored documents: encrypted at rest, retained for the duration set by your plan, then automatically deleted.
- Product analytics events: page views and product events (such as signups and renders) recorded per browser session and per API key, used to find where people get stuck. For lifecycle emails, your account email and plan are shared with our product analytics provider. No cross-site or advertising tracking.
- Rendered PDFs: unless you set store: true, a PDF rendered from HTML is held in a short-lived cache, scoped to your account, for up to 10 minutes so identical requests are served instantly, then discarded.
- Saved templates and schedules: the HTML you save with them, kept until you delete it.
03Data we never store
The following is processed in memory and discarded immediately after the render completes.
- The HTML source or URL you send us with a render request. It is not written to any persistent storage, except as part of a template or schedule you explicitly save.
- Credentials or session tokens from rendered pages.
- Webhook payloads sent to your endpoints.
- The content of rendered pages beyond the output PDF.
04Transport
All API traffic is encrypted in transit. We enforce TLS 1.2 as the minimum version. HSTS is enabled with a one-year max-age including subdomains. Plain-HTTP connections are redirected to HTTPS automatically.
TLS 1.2+HSTS enforcedHTTP to HTTPS redirect05Credentials
API keys are shown once on creation. After that, only the hashed form is stored. If you suspect a key has been exposed, rotate it instantly from your dashboard. Old keys stop working within 30 seconds of rotation.
shown once on creationhashed storage onlyrotation in one click06Responsible disclosure
If you find a security issue, email security@pdfpipe.xyz with a description and reproduction steps. We respond within 24 hours and will work with you on a coordinated disclosure timeline. We do not pursue legal action against good-faith researchers.
24h responsecoordinated disclosuresecurity@pdfpipe.xyz
Running a security review?
For security questionnaires, DPA requests or a deeper technical review, get in touch and it is handled personally.