Trust centre
Security at PDF Mixo
A clear summary of what is protected today and which controls apply to local documents and signed-in account data.
Last updated: September 24, 2026
Local document workspace
The main editor processes opened files in the browser. Local autosave stays in browser storage. Downloads are generated on the device. This reduces the need to transfer document contents to an application server.
Account protection
Email/password sign-in is delegated to Firebase Authentication and requires email verification. Sign in with ChatGPT remains available. Account APIs validate the active identity with the authentication provider, verify record ownership, validate input size, apply mutation throttling, restrict cross-site mutation requests, and mark private responses not to be cached.
Encryption tool
The optional PDF Mixo vault uses AES-256-GCM with a password-derived key in the browser. It creates a .dfsecure file rather than a standard password-protected PDF. PDF Mixo cannot recover a forgotten vault password.
Important limits
No browser tool can remove the need to inspect the final export. Proprietary embedded fonts, image-only scans, damaged PDFs, and unusual forms may require OCR or a fallback font. Keep an original backup and verify sensitive redactions in the downloaded file.
Responsible use
Do not upload or process documents you are not authorized to handle. Use account deletion controls when saved career information is no longer needed, and keep your browser and operating system updated.
