🛡 பாதுகாப்பு

JoyPDF-இல் பாதுகாப்பு

உங்கள் ஆவணங்கள் உயர்ந்த பாதுகாப்புக்கு தகுதியானவை. zero-upload architecture-ஆல் உங்கள் files சாதனத்தை விட்டு வெளியேறுவதில்லை.

கடைசியாக புதுப்பிக்கப்பட்டது: 16 ஏப்ரல், 2026

உள்ளூர் Processing

files முழுவதும் உங்கள் browser-இல் process செய்யப்படுகின்றன. எதுவும் upload செய்யப்படுவதில்லை.

Encrypted Transit

அனைத்து web traffic-உம் TLS 1.3 / HTTPS-ஆல் encrypted செய்யப்படுகிறது.

தானியங்கி சுத்தம்

browser memory-இல் உள்ள temporary data தானாக clear செய்யப்படுகிறது.

Architecture: Design-ஆல் Zero-Upload

JoyPDF-இன் security model பாரம்பரிய cloud-ஆதார PDF tools-இலிருந்து fundamentally வேறுபடுகிறது. processing-க்காக files-ஐ remote server-க்கு upload செய்வதற்குப் பதிலாக, WebAssembly (WASM) மற்றும் JavaScript பயன்படுத்தி அனைத்து operations-உம் locally உங்கள் browser-இல் run ஆகின்றன.

இதன் பொருள், உங்கள் sensitive documents — contracts, financial reports, medical records, legal filings — internet-ஐ traverse செய்வதில்லை. start-இலிருந்து finish வரை உங்கள் device-இல் இருக்கின்றன. server-side storage இல்லை, temporary cloud caching இல்லை, உங்கள் files-ஐ பாதிக்கும் server-side data breach-இன் வாய்ப்பும் இல்லை.

இந்த architecture security risks-இன் முழு categories-ஐயும் eliminate செய்கிறது:

  • உங்கள் files-க்கு data-in-transit risk இல்லை — அவை browser sandbox-ஐ விட்டு வெளியேறாது

  • server-side storage இல்லை என்பது cloud-ஆதார data leak-க்கு zero risk

  • உங்கள் document contents-க்கு third-party access இல்லை

  • residual data இல்லை — tab-ஐ close செய்தவுடன் processing data memory-இலிருந்து release ஆகிறது

பிணைய பாதுகாப்பு

joypdf.app-க்கும் அதிலிருந்தும் செல்லும் அனைத்து traffic-உம் TLS 1.3 மற்றும் strong cipher suites-ஆல் encrypted. அனைத்து endpoints-இலும் HTTPS enforce செய்கிறோம்; downgrade attacks-ஐத் தடுக்க HTTP Strict Transport Security (HSTS) implement செய்கிறோம்.

எங்கள் DNS records DNSSEC-ஆல் பாதுகாக்கப்படுகின்றன; cross-site scripting (XSS) மற்றும் code injection attacks-ஐ குறைக்க Content Security Policies (CSP) பயன்படுத்துகிறோம்.

எங்களால் implement செய்யப்படும் security headers:

  • `Strict-Transport-Security` — HTTPS-ஐ enforce செய்கிறது

  • `X-Content-Type-Options: nosniff` — MIME type sniffing-ஐத் தடுக்கிறது

  • `X-Frame-Options: DENY` — clickjacking-ஐத் தடுக்கிறது

  • `Referrer-Policy: strict-origin-when-cross-origin` — referrer leakage-ஐ limit செய்கிறது

  • `Content-Security-Policy` — resource loading-ஐ restrict செய்கிறது

AI Features: கட்டுப்படுத்தப்பட்ட Data Flow

AI-இயங்கும் features (AI Summary, AI Translate, AI Agent)-ஐ explicitly தேர்ந்தெடுக்கும்போது, extracted text content மட்டுமே எங்கள் secure API வழியாக AI processing partner-க்கு அனுப்பப்படுகிறது — original PDF file, images அல்லது metadata ஒருபோதும் அல்ல.

AI features-க்கான data flow:

  1. PDF-இலிருந்து text locally உங்கள் browser-இல் extract செய்யப்படுகிறது

  2. extracted text encrypted HTTPS வழியாக எங்கள் API endpoint-க்கு அனுப்பப்படுகிறது

  3. எங்கள் API request-ஐ AI model provider-க்கு forward செய்கிறது

  4. AI response stream ஆகி உங்கள் browser-இல் render செய்யப்படுகிறது

  5. request complete ஆன பிறகு text அல்லது response எங்கள் servers-இல் store செய்யப்படாது

model training-க்கு உங்கள் data-ஐ பயன்படுத்த AI providers-ஐ explicitly தடை செய்கிறோம். இது contractually enforce செய்யப்படுகிறது.

Authentication Security

User authentication Clerk-ஆல் handle செய்யப்படுகிறது — enterprise-grade identity platform. Clerk வழங்குவது:

  • bcrypt-ஆல் secure password hashing

  • Multi-factor authentication (MFA) support

  • OAuth 2.0 / OpenID Connect social login

  • secure, HttpOnly cookies-உடன் session management

  • Brute-force மற்றும் bot protection

  • SOC 2 Type II certified infrastructure

இணங்குதல் & தரநிலைகள்

JoyPDF பின்வருவற்றுக்கு comply செய்ய design செய்யப்பட்டுள்ளது:

  • GDPR — EU General Data Protection Regulation

  • CCPA — California Consumer Privacy Act

  • ePrivacy Directive — EU electronic communications privacy

  • LGPD — Brazil's General Data Protection Law

  • PIPEDA — Canada's Personal Information Protection and Electronic Documents Act

document data எங்கள் infrastructure-ஐ reach செய்வதில்லை என்பதால், zero-upload architecture compliance-ஐ inherently simplify செய்கிறது.

Responsible Disclosure

security vulnerabilities-ஐ seriously எடுத்துக்கொள்கிறோம். security issue-ஐ discover செய்தால், security@joypdf.app-இல் responsibly report செய்யவும். நாங்கள் commit செய்கிறோம்:

  • 48 hours-க்குள் உங்கள் report-ஐ acknowledge செய்தல்

  • remediation progress-இல் regular updates வழங்குதல்

  • good-faith security researchers-க்கு எதிராக legal action pursue செய்யாமல் இருத்தல்

  • discovered vulnerabilities-க்கு researchers-க்கு (அவர்களின் permission-உடன்) credit வழங்குதல்

பாதுகாப்பு குழுவைத் தொடர்பு கொள்ளுங்கள்

பாதுகாப்பு அறிக்கைகள்: security@joypdf.app

பொது: contact@joypdf.app

சேவை: JoyPDF · joypdf.app