Security
What actually happens to your file when you use a tool here — no certifications we haven't earned, just what's true today.
Encrypted in transit
Every upload and download runs over TLS (HTTPS). Your file never crosses the network unencrypted.
Processed, then deleted
Files are processed in memory or briefly on disk to run the requested tool, then deleted. We don't archive uploads or keep a copy after the job finishes.
AES-256 on Password Protect
The Password Protect tool applies real AES-256 encryption to the output file — the same standard used for banking and government data — not a cosmetic lock.
No signup, no tracking profile
Free tools require no account, so there's no identity to build a profile against in the first place.
Your documents aren't used to train anything
Files you upload are never used to train AI models, ours or anyone else's.
Card details never touch our servers
Pro checkout runs entirely on Stripe's own hosted page — a PCI DSS Level 1 certified payment processor, the highest tier of that certification. We never see, transmit, or store your full card number.
Watch for impersonators
iguardpdf.com is our only real domain, and we'll never ask for your password by email or DM. If you're contacted by someone claiming to be iGuardPDF anywhere else, treat it as fraudulent and report it to us.
Tool-by-tool security notes
Merge, Split, Compress, Sign, Watermark
Processed and deleted, same as any free tool. Optional free watermark/password/copyright add-ons available on the output.
Password Protect
Real AES-256 encryption via a dedicated encryption library — independently verified against poppler's pdftotext during development, not just our own code checking its own work.
Unlock
Only removes a password you already have — we never attempt to crack or brute-force protected files.
Pro Guarded fingerprint
A unique, invisible identifier embedded per document, tied to your account so a leaked copy can be traced back. Stored separately from the document content.
Infrastructure
We build on established providers rather than running our own servers — fewer places for something to go wrong, and each provider brings its own security practices on top of ours.
Vercel
Hosting & compute
Neon
Postgres database
Supabase
Encrypted storage (Pro only)
Clerk
Authentication
Encryption at rest (Pro features)
Anything we do store for Pro features (like fingerprint records) uses envelope encryption where applicable — a unique, randomly generated key per item, itself encrypted by a master key, rather than one shared key protecting everything. If one item's key were ever compromised, it wouldn't expose anything else.
Responsible disclosure
Found a security issue? We don't run a paid bug bounty program today, but we take reports seriously and will credit you publicly if you'd like. Email the address below with what you found and how to reproduce it. We aim to acknowledge within 48 hours and keep you updated until it's resolved — please give us a reasonable window to fix something before disclosing it publicly.
Document security features
This page covers how we handle your files and infrastructure. For the document-level security features available on Guarded documents — fingerprinting, revocation, burn-after-read, and secure sharing — see:
Found a security issue? Email iguardpdf@hotmail.com with "Security" in the subject line — we read those first. For how we handle your data more broadly, see our Privacy Policy.