Security Safeguards & Architecture
A clear, factual explanation of the security controls and data protections actually implemented across the DOCUMENTFORGE platform.
Last reviewed:
No computer system or cloud service is 100% secure. We do not make unfounded marketing assertions such as "unhackable" or "flawless protection". What we provide is an architectural commitment to minimization: files are temporary, access is restricted, credentials are encrypted, and documents are automatically purged.
If you are handling documents subject to strict regulatory air-gapping requirements, please evaluate whether any internet-based SaaS utility meets your operational constraints before uploading sensitive files.
1. Ephemeral Storage & Automatic Purge
The core privacy safeguard in DOCUMENTFORGE is strict data minimization through automatic deletion:
- Strict Retention Schedule: Uploaded input documents and generated output files have a strict time-to-live: 1 hour for Free tier users (both anonymous and registered) and 24 hours for Pro tier subscribers.
- On-Access Expiration Verification: When a user attempts to download or query a job, the server verifies its expiration timestamp (
expiresAt). Once expired, the job transitions toEXPIREDand downloads are permanently refused with HTTP 410. - Local Server Storage: Uploaded files reside in dedicated temporary directories on the local processing server filesystem (
.storage/). Files are never copied to external cloud object stores or distributed replication systems. - Zero Secondary Backups: We do not create cold backups, unlinked shadow copies, or long-term snapshots of customer document contents. Once deleted, file content cannot be restored.
2. Private Document Access Control
Your documents are private to you and protected by server-side authorization checks:
- User Boundary Enforcement: When an authenticated user processes a document, the job is linked to their account. The download endpoint strictly verifies that the requesting session matches the job's owner. User A cannot view or download documents belonging to User B.
- Anonymous Session Isolation: For unauthenticated users, processing operations are tied to an opaque, cryptographically random session identifier.
- No Human Document Review: All document transformations are performed exclusively by automated software engines. Team members do not open, view, or review document contents during routine operations.
- No AI/ML Model Training: Uploaded documents, text extracts, OCR transcripts, or spreadsheet outputs are never used to train, evaluate, or fine-tune artificial intelligence or machine learning models.
3. Input Validation & Defense in Depth
All user inputs and uploaded files undergo multi-layer verification before processing:
- Magic Bytes Verification: The server inspects initial file headers to verify true file format (e.g.
%PDF-magic bytes for PDF, binary headers for PNG, JPEG, WEBP), preventing malicious executable payloads masquerading as documents. - Extension & MIME Enforcement: Files must match explicitly allowed input extensions for the requested utility.
- File & Batch Size Limits: File sizes are strictly checked against tier limits (up to 25 MB for anonymous, 50 MB for free registered, 250 MB for Pro). A global 100 MB per-batch limit and max file counts prevent memory exhaustion.
- Filename Sanitization: Input filenames are sanitized to strip shell metacharacters and invalid path characters.
4. Path Traversal & Injection Protection
System boundaries are enforced at the filesystem and database layers:
- Job ID Sanitization: Job IDs are restricted to alphanumeric and hyphen characters (
DF-[A-Z0-9]+), stripping any sequence that could traverse directories. - Path Confinement: All storage access uses
path.resolveandpath.basenameto ensure file reads and writes remain strictly confined within their designated subdirectories. - Parameterized Database Queries: All database operations utilize Drizzle ORM with parameterized queries, preventing SQL injection vulnerabilities.
5. Account & Authentication Security
Account authentication is designed using modern cryptographic standards:
- Scrypt Password Hashing: Passwords are hashed using the memory-hard scrypt algorithm (
N=32768, r=8, p=1) with cryptographically random salts. Plaintext passwords are never stored or logged. - 256-bit Random Session Tokens: Sessions use 32-byte (256-bit) cryptographically random hexadecimal strings generated via
crypto.randomBytes. - Session Fixation Defense: When a user logs in or registers, existing session tokens are explicitly destroyed before a new session is issued.
- Timing Side-Channel Defense: During login authentication, if an email is not found, a constant-time dummy scrypt verification is executed to mitigate user enumeration through timing analysis.
- Cookie Protections: Session cookies are marked
HttpOnly(inaccessible to JavaScript),SameSite=Lax(cross-site request mitigation), andSecurein production environments (HTTPS transmission only).
6. Abuse Mitigation & Operational Timeouts
- Sliding-Window Rate Limits: Authentication endpoints enforce IP-based rate limiting (10 registration attempts per 15 min; 15 login attempts per 15 min) tracked in database storage.
- Atomic Quota Reservations: Daily and monthly processing quotas are verified and reserved atomically, preventing concurrency race conditions.
- Processing Timeouts: Document processing tasks have an execution timeout limit (300 seconds default) to terminate hung or pathological document rendering loops.
7. Payment Data Isolation
Payment transactions are isolated from our application infrastructure:
- Payment Processor Delegation: Subscriptions are processed by Cashfree Payments India Pvt. Ltd. through their hosted payment checkout.
- Zero Cardholder Data Storage: DOCUMENTFORGE servers never receive, transmit, or store credit card numbers, debit card numbers, CVVs, or netbanking credentials.
- HMAC Webhook Verification: Webhook notifications from Cashfree are verified using HMAC-SHA256 signatures with timestamp checks before updating local subscription states.
- Webhook Idempotency: Webhook events are logged in a database idempotency table to prevent duplicate entitlement crediting.
8. What We Do NOT Claim
In the interest of full transparency, we explicitly state what is NOT part of our security scope:
- We do NOT hold formal SOC 2, ISO 27001, or third-party certifications at this stage.
- We do NOT claim PCI-DSS certification directly; payment processing is delegated to Cashfree's PCI-certified environment.
- We do NOT perform antivirus or malware scanning on uploaded documents.
- Uploaded documents reside as standard temporary files on server storage during their retention window; they are not client-side encrypted with user-held cryptographic keys.
Vulnerability Reporting & Security Contact
If you identify a security vulnerability or potential privacy exposure in DOCUMENTFORGE, please report it responsibly so we can remediate it promptly:
[OWNER: Security email not configured — set LEGAL_SECURITY_EMAIL before launch]
Please include reproduction steps, affected endpoints, and impact assessment. We aim to acknowledge reports within 2 business days.