Security
SumoPDF is a static site with browser-local tools, which keeps its attack surface small.
Architecture
The site is static HTML, CSS, and JavaScript served over HTTPS. The PDF tools run entirely in your browser. There is no application server that receives your documents, and no document database.
Controls
HTTPS. A Content Security Policy that restricts scripts and styles to SumoPDF's own origin. The PDF library is served from SumoPDF, not a third-party CDN, and its file is pinned by content hash. No advertising, session replay, or document-aware analytics on the tool pages.
Reporting a vulnerability
Report any security or privacy issue to security@sumopdf.com with enough detail to reproduce it. Our /.well-known/security.txt lists the current contact. Please give us reasonable time to address an issue before disclosing it publicly.