Security

Phase 1 tools validate inputs, apply device-aware size and memory limits, and isolate heavy processing in workers where practical. Outputs are verified before download enable on PDF and image paths.

Transport uses HTTPS. Security headers (including CSP in report-only mode during rollout) are configured in the application. Dependency licenses and engines are recorded in ADRs under docs/adr/.

Report suspected vulnerabilities via the contact page.