Skip to content

§ Data handling

HTML to PDF API security

Your documents are your business. Here is how Sitepdf is being built to handle them, and, stated plainly, which enterprise controls are shipped versus planned.

The architecture, in one paragraph

A render is transient by default. Your HTML or the fetched page enters an isolated rendering context, the PDF is produced, the response is returned, and the working copy is discarded. Nothing persists unless you asked for an archive, in which case the snapshot is written to storage scoped to your account and nowhere else. Render contexts are single-tenant per job: no two customers' pages ever share a browser process.

Encryption in transit

All API traffic is TLS only, including retrieval of stored archives and documents. Plain HTTP is refused, not redirected.

Tenant isolation

Every render job runs in its own isolated browser context, torn down after the job. Archives are stored under your account id and are not listable or retrievable by anyone else.

Retention and deletion

Archive retention follows your plan window. Deletion, on schedule or on request, is a real delete of the stored snapshot, not a soft flag.

Transient by default

No archive flag, no storage. The default mode of the API keeps nothing of your content after the response is sent.

Least-data signup

The early-access list stores an email, a confirmation status and the page you signed up from. That is the entire dataset this website collects about you.

Invoicing and DPA

Enterprise agreements with a data processing addendum and invoice billing are available from day one of the enterprise tier.

Planned for launch, labelled as planned

  • SSO and role-based access for teams and audit-sensitive orgs.
  • 99.9% uptime SLA on enterprise, with public status reporting.
  • Data residency options so archives can be pinned to a region.
  • Integrity checksums exposed in the API so any snapshot can be independently verified.

We do not hold a SOC 2 or ISO 27001 certificate today, and we will not imply otherwise. When an audit is underway or complete, this page will say so, with dates. Until then: the honest status is "security-first architecture, certification on the roadmap".

For engineering and compliance leaders

The reason compliance teams look at Sitepdf is usually not the PDF at all: it is the archive. Timestamped, retrievable snapshots of rendered pages answer audit and e-discovery requests that screenshots in a shared drive cannot, and retention control means your records policy, not ours, decides what exists. Our compliance archiving guide covers what makes a snapshot defensible.

Questions, requirements, or a security questionnaire to fill in? Email [email protected] and a person who can answer precisely will reply.

§ Early access

Get on the early-access list

The API opens to the list first, in order. Early access locks the planned launch rates for 12 months. No card required, launching soon.

Render + archive, one API