Security & Trust Hub

At Siliph, we believe document tasks shouldn't compromise your data safety. This hub explains how we protect your privacy, encrypt files during transit and at rest, and keep operations local to your browser whenever possible.

1. Browser-local execution (No uploads)

Most of our basic PDF tools—including Merge PDF, Split PDF, Rotate PDF, Delete Pages, and Page Numbers—operate completely in your web browser.

  • Your files are loaded into your browser's memory and processed locally using JavaScript and WebAssembly.
  • No file contents ever leave your device or reach our servers.
  • Processing completes instantly even without an internet connection once the page is loaded.

2. Secure transit & encrypted cloud storage

For complex operations that require server processing (such as OCR, heavy document compression, and high-fidelity file conversions), files must be sent to our secure backend:

  • TLS 1.3 Encryption: All files are encrypted in transit using industry-standard Transport Layer Security (HTTPS) to prevent interception.
  • Encrypted Storage at Rest: Files are stored in secure, private cloud buckets (Cloudflare R2) using AES-256 server-side encryption.
  • Data Isolation: Each processing job is containerized in an isolated environment. Your files are never accessible to other users or public networks.

3. Automatic 2-hour deletion policy

We strictly enforce a short file retention window for all server-processed documents to minimize the risk of data exposure:

  • Free tier: Files are automatically, permanently, and irreversibly deleted from our storage buckets exactly 2 hours after the processing job completes.
  • Manual deletion: You can choose to delete your files from our servers immediately by clicking the delete button on the download page.
  • We do not keep backups or archive logs of your document contents. Once deleted, they are gone forever.

4. Strict data usage & privacy standards

Your document data belongs entirely to you. Siliph operates under strict guidelines:

  • We **never** sell, rent, or share your document contents, metadata, or personal data with third-party advertisers.
  • We do **not** use your uploaded documents or text contents to train AI models (like Gemini or GPT).
  • All AI integrations (such as document summaries or advisory prompts) are processed securely using official developer API contracts that do not retain data for model training.

5. Infrastructure & threat protection

Our application is hosted on secure cloud infrastructure managed in high-grade data centers. We deploy active threat mitigation:

  • DDoS & WAF Protection: We use Cloudflare Web Application Firewall to detect and mitigate malicious traffic, SQL injection, and cross-site scripting (XSS) threats.
  • Access Controls: Standard least-privilege principles are enforced for our internal environment. No staff member has routine access to file storage directories.

Have questions about document safety, compliance, or premium billing? Please contact our privacy and support team at Contact us or read our complete Privacy Policy.