Security
We take the security and privacy of your files seriously. This page explains the security measures we implement to protect your data when using Docswift.
While we implement strong security practices, we want to be transparent: no online service can guarantee absolute security. We continuously work to improve our security measures, but we encourage users to exercise judgment when uploading sensitive documents to any online service.
Security Practices
Encrypted Transfers
All file uploads and downloads are protected with HTTPS/TLS encryption. Your files cannot be intercepted during transfer.
Automatic Deletion
Uploaded files are automatically deleted from our servers within minutes after processing is complete. We do not permanently store user files.
Secure Processing
Files are processed in isolated server environments. Each conversion job runs independently, and temporary files are cleaned up immediately after processing.
No Content Access
We do not read, analyze, or access the contents of your uploaded documents. Files are processed programmatically without human review.
Security Headers
The platform implements security headers including HSTS, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy to protect against common web attacks.
Abuse Prevention
We implement rate limiting, file size limits, and file type validation to prevent abuse and protect the platform from malicious use.
File Handling Details
- Files are uploaded via HTTPS to our processing servers.
- Each uploaded file receives a random identifier — original filenames are not used for storage.
- Files are processed in temporary storage that is automatically cleaned.
- Completed conversions are available for download briefly, then deleted.
- Failed conversions are cleaned up immediately.
What We Validate
- File type (MIME type and file extension)
- File size (configurable limits per tool)
- File signature (magic byte validation where applicable)
- Filename sanitization (path traversal prevention)
Reporting Security Issues
If you discover a security vulnerability, please contact us at tonovoxtechnologies@gmail.com with details. We appreciate responsible disclosure and will investigate all legitimate reports.