Security

How we protect your files and account, and how to report a security problem.

We protect your files and your account in the ways listed below. You can also read what you can do to stay safe, and how to report a security problem.

01Your files

  • Some work never leaves your device. Viewing pages, reading a PDF’s existing text, and the editing you do before you save all happen in your browser.
  • Files that need our servers are uploaded with industry-standard encryption in transit.
  • Each file is processed in isolation from other users’ files.
  • File type and size are checked before processing.
  • Text recognition runs on our own servers. Scans are not sent to an outside recognition service.
  • Your file stays on our server only for a short time while it is processed, then it is deleted. Tools that work in several steps keep it for up to 30 minutes after you last use it. Request Signatures keeps documents until you delete them.

The Privacy Policy gives the full details.

02Your account

  • Passwords are stored only in a strongly hashed form using an industry-standard algorithm. We never store the password itself.
  • Session tokens are also stored only in hashed form.
  • Our cookies are secured so that page scripts cannot read them.
  • Signing out ends your session on our servers straight away.
  • Resetting your password signs you out on every device.
  • For security reasons, after several failed sign-in attempts in a row, the account is locked for a short time. We also limit how many requests can be made to the service.

03What you can do

  • Use a password you do not use anywhere else.
  • Sign out when you use a shared or public computer.
  • Keep your original files. KovaPDF is not a backup service.
  • Be careful with emails that claim to be from us. We will never ask for your password, or ask you to send a document by reply.

04Reporting a vulnerability

If you find a security flaw, email support@kovapdf.com with the page or endpoint, the steps to reproduce it, and what you were able to do.

We will:

  • reply within 5 working days;
  • tell you what we found and when we expect to fix it;
  • tell you when it is fixed, and credit you if you wish;
  • not take legal action against research done within the rules below.

We ask you to:

  • test only with your own account and files, and stop and tell us if you reach anyone else’s data;
  • not disrupt the service, for example with denial-of-service attacks or heavy automated scanning;
  • give us reasonable time to fix the issue before you publish it. Our default is 90 days.

05If something goes wrong

If a security breach affects your data, we will tell you promptly, explain what happened and what was involved, and say what you should do.