Security
Reduce trust, then test the boundary
JadePDF's launch security model avoids document uploads, bundles the PDF runtime, and blocks releases when automated checks fail.
Local document processing
18 verified launch tools process document bytes in the browser and expose no JadePDF upload endpoint.
Bundled PDF runtime
PDF.js and its module worker are served from the same release. PDF scripting, XFA, dynamic evaluation, and fake-worker fallback are disabled.
Fail-closed release gate
High or critical dependency advisories, build failures, recovery-test failures, browser errors, worker failures, or unexpected uploads block release.
Static hosting boundary
Cloudflare serves the application with restrictive security headers. There is no production database or document-processing backend in the launch architecture.
Automated release checks
The production branch is expected to pass all of the following before deployment:
- Locked dependency installation with
npm ci. - Dependency audit that blocks high and critical advisories.
- Astro production build.
- Deterministic recovery and capability tests.
- Chromium tests using synthetic PDFs and the bundled PDF.js worker.
- Network assertions that reject unexpected external requests and document uploads.
Production response controls
Cloudflare Pages receives a content security policy, clickjacking protection, MIME-sniffing protection, a strict referrer policy, limited browser permissions, immutable caching for fingerprinted assets, and no-store caching for the service worker.
Known limitations
Browser-local processing does not make arbitrary PDFs harmless. Malformed or adversarial documents can still consume device resources or expose defects in browser libraries. JadePDF uses input limits, disabled PDF scripting, explicit errors, and dependency updates to reduce that risk, but users should avoid opening untrusted files and retain originals.
JadePDF does not certify PDF/A conformance, accessibility, digital-signature validity, evidentiary admissibility, irreversible redaction, or suitability for a regulated workflow unless a specific tool page explicitly states and verifies that capability.
Processing details
See Privacy architecture for the document flow and Privacy Policy for data practices.