VelloDoc processes documents on its server, so this page explains how uploads are protected from the moment they leave your browser until they're deleted.
Encrypted connections
Every page, upload and download is served over HTTPS, which encrypts the traffic between your browser and VelloDoc.
Isolated temporary jobs
Each request gets its own temporary job folder with a random, unpredictable name. The tool reads your upload from that folder and writes the result next to it, and the result is streamed back in the same response. There are no public or guessable download links.
Deletion
- Successful jobs: the folder, including your upload and the result, is deleted when the download finishes or the connection closes.
- Failed jobs: the folder is deleted immediately.
- Interrupted jobs: a cleanup that runs every 1 minute deletes job folders older than 30 minutes.
Share links
Files shared with Share PDF Link are the one exception to deletion after download. Each file is encrypted with AES-256-GCM using its own random key, and that key isn't stored on the server. It's part of the link, after the # sign. The server keeps only a check value to reject wrong keys, a one-way scrambled version of any link password, and a one-way scrambled version of the manage link's code. For view only links, pages are drawn as images while someone is viewing, kept in encrypted form, and the PDF itself is never sent. Files are deleted when the link expires or is turned off, and the access history one day later.
Passwords
Passwords you type to open a protected PDF, or to protect one, are sent with the job over HTTPS, used only for that file and deleted with the job folder. VelloDoc doesn't keep them or write them to its logs.
Limits that protect the service
Uploads are limited to 80 MB per request and processing to 5 minutes per job. Each IP address can start 60 processing jobs and 120 PDF inspections every 15 minutes, and upload requests sent from other websites are refused. The limits page lists every limit.
Safeguards for risky inputs
- Web Page to PDF only fetches public web addresses. Private, loopback, link-local and reserved network addresses are refused, including after every redirect, and each downloaded resource is capped at 25 MB.
- Uploaded HTML files are rendered with scripts removed and remote and local resources blocked.
- SVG files that reference external or local files are rejected.
- EPUB images are taken from inside the ebook itself. Nothing is fetched from the internet.
Browser protections
Pages are sent with strict browser security rules (a Content-Security-Policy plus X-Frame-Options, Referrer-Policy, Permissions-Policy, X-Content-Type-Options and Cross-Origin-Opener-Policy headers). These limit what can run on the site and stop other websites from showing it inside their own pages.
Real redaction
Redact PDF deletes the text and images inside the areas you mark before the file is saved. It doesn't just draw a black box over content that could still be copied.
Server-side processing, stated plainly
VelloDoc isn't an in-browser tool. Your files are uploaded to VelloDoc's server, where open-source engines like PyMuPDF, Ghostscript, LibreOffice and Tesseract do the work. That makes demanding conversions possible, but it means each file leaves your device while the job is running. Your documents aren't sent to a third-party conversion service. If a document must never leave your device, use offline software instead. The one exception is the AI PDF Workspace: when you ask the AI a question and agree to it, the text taken from your PDFs is sent to Anthropic to write the answer.
Reporting a security problem
If you find a vulnerability, please report it through the contact form, and don't access other people's data while testing.