TLS
All production traffic should use HTTPS/TLS with secure cookies where accounts are introduced.
Security
Local tools reduce server exposure. Cloud, AI, OCR, and API workflows need explicit isolation, retention, and access controls.
All production traffic should use HTTPS/TLS with secure cookies where accounts are introduced.
Planned cloud jobs should use encrypted object storage and signed URLs.
Future cloud files should be accessed through short-lived signed URLs, not public buckets.
Uploaded files in cloud workflows should be scanned and isolated before worker processing.
Cloud PDF workers should run with CPU, memory, time, filesystem, and network controls.
The web viewer should not execute PDF JavaScript/actions while previewing untrusted documents.
Report security concerns to security@clearpdf.net. Include reproduction steps and affected URLs when possible.
DPA, subprocessors, audit logging, regional processing, SSO, SCIM, and enterprise controls are Phase 3 or later.
Backend status
These checks come from backend readiness data and retained-evidence gates. They do not replace live TLS, storage, malware, or deployment evidence.
Build local-build-unset; release domain api.clearpdf.net; retained evidence missing items 0.