Security

How DocsNest protects you when you open documents from unknown sources, and how protection features work.

Imported PDFs are treated as untrusted

PDF files can contain scripts, links and malformed structures. DocsNest never executes JavaScript embedded in a PDF. Files are parsed by hardened engines inside your browser’s sandbox, and form XFA scripting is disabled.

Strict content security policy

The website only runs code from its own origin. A content security policy blocks third-party scripts, inline script injection, framing by other sites and plug-ins. Core engines are bundled and served from our own domain rather than external CDNs.

Encryption

Protect PDF encrypts documents with AES-256, the strongest standard PDF encryption. Permissions such as printing and copying restrictions are recorded in the file, but they are enforced by the PDF reader. Some readers ignore them, so use an open password when content must stay confidential.

Redaction removes content

Redact PDF does not simply draw black boxes. Pages containing redactions are rebuilt from a rendered image with the marked areas removed, and the original page content, annotations and hidden objects are discarded. Remaining text is restored as a searchable layer, excluding anything inside the redacted areas.

Passwords

Passwords you enter are used once, in memory, to decrypt or encrypt a file. They are never stored, logged or transmitted. DocsNest does not offer password cracking or removal of protection from documents you cannot open.

Reporting a vulnerability

If you believe you have found a security issue, please contact us. We appreciate responsible disclosure and will respond as quickly as possible.

hello@docsnest.com