Zero-Upload Architecture

Every tool runs entirely in your browser. Your files are processed locally and never uploaded to any server.

Client-Side Processing

All image compression, PDF merging, and file conversion happens directly on your device in a sandboxed environment.

No Data Collection

We do not collect, store, or transmit any personal data, file content, or usage information to external servers.

Encrypted Connection

All pages are served over HTTPS with TLS encryption. HSTS headers ensure your browser always uses a secure connection.

Open Source

Our source code is publicly available on GitHub. Anyone can audit our code.

No Accounts Required

We never ask for registration, email, or personal information. No accounts, no passwords, no data associated with your usage.

Security Headers

HSTS Forces HTTPS for all connections
CSP Prevents XSS and unauthorized script injection
X-Frame-Options Prevents clickjacking via iframe embedding
Permissions-Policy Blocks camera, microphone, geolocation APIs
X-Content-Type Prevents MIME-type sniffing attacks
Referrer-Policy Limits referrer information leakage

Have a Security Concern?

If you discover a vulnerability, reach out to us directly.

formfix.support@gmail.com