Pagelea

Security

Your files deserve a short trip.

For the eight published workflows, document bytes stay inside your browser. Pagelea’s open-source, local-processing architecture reduces the systems that can receive a private file.

Last updated 26 July 2026

01

Local document processing

The eight published workflows process document bytes on your device. The Worker has no document-upload, remote conversion or persistent file-library endpoint.

02

Verifiable implementation

Pagelea Community is open source under AGPL-3.0-or-later. Reviewers can inspect the document path, resource limits and network boundaries instead of relying only on a privacy claim.

03

Bounded, defensive parsing

Pagelea limits file count, bytes, pages, decoded image pixels, editor elements, text and nested PDF objects before expensive work. Unsupported or over-limit input fails closed with a specific error.

04

A deliberately small server surface

Only optional aggregate analytics ingestion and an allowlisted administrative analytics read are routed through the public Worker. API methods and request bodies are bounded and allowlisted, unknown paths fail closed, and responses receive restrictive security headers.

05

Responsible reporting

Report a suspected vulnerability to hello@pagelea.com with reproducible steps, affected paths and expected impact. Do not include credentials, private documents or unnecessary personal data, and do not test against systems or data you do not own.

06

Honest limits

Sanitize & Flatten reduces the active structures covered by its documented checks, but no PDF tool can certify that an adversarial file is harmless. Scanned text requires OCR, and complex fonts or layouts may not be editable.

Ready when you are

Put a PDF in its place.

Explore all tools