🛡 सुरक्षा

JoyPDF मध्ये सुरक्षा

आपले दस्तऐवज सर्वोच्च स्तराच्या संरक्षणास पात्र आहेत. आमचे zero-upload आर्किटेक्चर म्हणजे आपली फाइल्स डिव्हाइस सोडत नाहीत.

शेवटचे अपडेट: 16 एप्रिल, 2026

स्थानिक प्रक्रिया

फाइल्स पूर्णपणे आपल्या ब्राउझरमध्ये प्रक्रिया होतात. काहीही अपलोड होत नाही.

Encrypted Transit

सर्व web traffic TLS 1.3 / HTTPS ने encrypted.

Auto-Cleanup

ब्राउझर memory मधील temporary data automatically clear होते.

आर्किटेक्चर: Design द्वारे Zero-Upload

JoyPDF चे security model traditional cloud-आधारित PDF साधनांपेक्षा मूलभूतपणे वेगळे आहे. प्रक्रियेसाठी फाइल्स remote server वर अपलोड करण्याऐवजी, सर्व ऑपरेशन्स WebAssembly (WASM) आणि JavaScript वापरून आपल्या ब्राउझरमध्ये स्थानिक चालतात.

याचा अर्थ आपले संवेदनशील दस्तऐवज — contracts, financial reports, medical records, legal filings — internet ओलांडत नाहीत. ते सुरुवातीपासून शेवटपर्यंत आपल्या डिव्हाइसवरच राहतात. server-side storage नाही, temporary cloud caching नाही, आणि server-side data breaches आपल्या फाइल्सना affect करण्याची शक्यता नाही.

हे आर्किटेक्चर security risks च्या entire categories eliminate करते:

  • आपल्या फाइल्ससाठी data-in-transit risk नाही — त्या browser sandbox सोडत नाहीत

  • server-side storage नाही म्हणजे cloud-based data leaks चा zero risk

  • आपल्या document contents ला third-party access नाही

  • residual data नाही — टॅब बंद केल्यावर processing data memory मधून release

Network Security

joypdf.app कडे आणि त्याकडून सर्व traffic TLS 1.3 आणि strong cipher suites ने encrypted. सर्व endpoints वर HTTPS enforce करतो आणि downgrade attacks रोखण्यासाठी HTTP Strict Transport Security (HSTS) implement.

DNS records DNSSEC ने protected, आणि cross-site scripting (XSS) आणि code injection attacks mitigate करण्यासाठी Content Security Policies (CSP) वापरतो.

आम्ही implement केलेले security headers:

  • `Strict-Transport-Security` — HTTPS enforce

  • `X-Content-Type-Options: nosniff` — MIME type sniffing रोखते

  • `X-Frame-Options: DENY` — clickjacking रोखते

  • `Referrer-Policy: strict-origin-when-cross-origin` — referrer leakage मर्यादित

  • `Content-Security-Policy` — resource loading restrict

AI Features: Controlled Data Flow

जेव्हा आपण स्पष्टपणे AI-संचालित वैशिष्ट्ये (AI Summary, AI Translate, AI Agent) वापरणे निवडता, तेव्हा फक्त extracted text content secure API द्वारे AI processing partner कडे पाठवले जाते — कधीही original PDF file, images किंवा metadata नाही.

AI features साठी data flow:

  1. PDF मधून text आपल्या ब्राउझरमध्ये स्थानिक extract

  2. Extracted text encrypted HTTPS द्वारे API endpoint वर पाठवले

  3. API request AI model provider कडे forward

  4. AI response stream होऊन ब्राउझरमध्ये render

  5. request complete झाल्यावर text किंवा response servers वर store नाही

आम्ही contractually आमच्या AI providers ला model training साठी आपला डेटा वापरण्यास प्रतिबंधित करतो. हे contractually enforce केले जाते.

Authentication Security

User authentication Clerk द्वारे manage होते, enterprise-grade identity platform. Clerk provides:

  • bcrypt सह secure password hashing

  • Multi-factor authentication (MFA) support

  • OAuth 2.0 / OpenID Connect social login

  • secure, HttpOnly cookies सह session management

  • Brute-force आणि bot protection

  • SOC 2 Type II certified infrastructure

Compliance आणि Standards

JoyPDF खालील गोष्टींचे अनुपालन करण्यासाठी design केला आहे:

  • GDPR — EU General Data Protection Regulation

  • CCPA — California Consumer Privacy Act

  • ePrivacy Directive — EU electronic communications privacy

  • LGPD — Brazil's General Data Protection Law

  • PIPEDA — Canada's Personal Information Protection and Electronic Documents Act

आमचे zero-upload architecture inherently compliance simplify करते कारण document data कधीही आमच्या infrastructure पर्यंत पोहोचत नाही.

Responsible Disclosure

आम्ही security vulnerabilities seriously घेतो. security issue discovered असल्यास, कृपया security@joypdf.app वर responsibly report करा. आम्ही commit करतो:

  • 48 तासांच्या आत आपल्या report ची acknowledge

  • remediation progress वर regular updates

  • good-faith security researchers विरुद्ध legal action न घेणे

  • discovered vulnerabilities साठी researchers ला (त्यांच्या permission सह) credit

Security Team शी संपर्क

Security reports: security@joypdf.app

सामान्य: contact@joypdf.app

सेवा: JoyPDF · joypdf.app