Security policy
Reporting a vulnerability
Email security@remixpdf.io with a description, the steps to reproduce, and what you think the impact is. You will get a human reply. We ask that you give us a reasonable window to fix before you publish — we will tell you what we are doing and when it lands.
The machine-readable pointer lives at /.well-known/security.txt.
Scope
In scope, and the reports most useful to us:
- The site and editor at remixpdf.io, and the assist backend at api.remixpdf.io.
- Anything that lets one user's document reach another user, or reach us when it should not.
- Script injection that runs inside a tool route (they carry a strict no-egress CSP — proving a way through it is a real finding).
- The vendored engines' parsing of hostile files, where our own patches are at fault.
Out of scope:
- Vulnerabilities in third-party software we have not modified — report those upstream (the components and their upstreams are listed at /notices).
- Denial-of-service by volume, and social engineering.
Ground rules
- Use only test documents you created or own. If a proof needs a real document, redact it first.
- Do not access, change or delete anyone else's data, and do not degrade the service for others.
- Good-faith research reported this way will not be treated as hostile. We will not pursue or support legal action against it.
What to expect
- An acknowledgement, then a substantive reply once we have reproduced it.
- A fix shipped, and credit if you would like it — by name or handle, on this page or in the release notes.
Last updated 2026-08-01.