Security we actually provide
These are product controls, not third-party compliance certifications. If a badge is not listed here, we do not claim it.
Last updated 28 August 2026
What this page is not
SoHappyPDF does not publish third-party audit reports or compliance certifications. This page describes how the product handles files, accounts, and API keys today.
Files stay scoped and temporary
Uploads and results are tied to your anonymous session or signed-in account, not a shared library. Downloads use short-lived signed URLs rather than public object links. Temporary files expire after about two hours. Presigned upload and download URLs expire after 15 minutes.
Accounts are authorized on the server
The account area uses email and password authentication. File, conversion, billing, and API key actions are authorized on the server. Client-side checks are not a permission grant.
API keys are secrets
Programmatic access uses a Bearer API key. Do not put keys in URLs, browser JavaScript, or source control. If a key leaks, delete it in the account area and create a replacement.
Report a security issue
If you find a vulnerability in SoHappyPDF, email us with enough detail to reproduce it. Do not attach customer files. We will not ask you to send API keys or passwords.
Questions about these pages go to hello@sohappypdf.com