Security

Reduce trust, then test the boundary

JadePDF's launch security model avoids document uploads, bundles the PDF runtime, and blocks releases when automated checks fail.

Local document processing

18 verified launch tools process document bytes in the browser and expose no JadePDF upload endpoint.

Bundled PDF runtime

PDF.js and its module worker are served from the same release. PDF scripting, XFA, dynamic evaluation, and fake-worker fallback are disabled.

Fail-closed release gate

High or critical dependency advisories, build failures, recovery-test failures, browser errors, worker failures, or unexpected uploads block release.

Static hosting boundary

Cloudflare serves the application with restrictive security headers. There is no production database or document-processing backend in the launch architecture.

Automated release checks

The production branch is expected to pass all of the following before deployment:

  • Locked dependency installation with npm ci.
  • Dependency audit that blocks high and critical advisories.
  • Astro production build.
  • Deterministic recovery and capability tests.
  • Chromium tests using synthetic PDFs and the bundled PDF.js worker.
  • Network assertions that reject unexpected external requests and document uploads.

Production response controls

Cloudflare Pages receives a content security policy, clickjacking protection, MIME-sniffing protection, a strict referrer policy, limited browser permissions, immutable caching for fingerprinted assets, and no-store caching for the service worker.

Known limitations

Browser-local processing does not make arbitrary PDFs harmless. Malformed or adversarial documents can still consume device resources or expose defects in browser libraries. JadePDF uses input limits, disabled PDF scripting, explicit errors, and dependency updates to reduce that risk, but users should avoid opening untrusted files and retain originals.

JadePDF does not certify PDF/A conformance, accessibility, digital-signature validity, evidentiary admissibility, irreversible redaction, or suitability for a regulated workflow unless a specific tool page explicitly states and verifies that capability.

Processing details

See Privacy architecture for the document flow and Privacy Policy for data practices.