Security at FORMARTIO
Your privacy and file integrity are the foundation of every tool. Here we explain how we protect your data, which standards we meet, and what we never store.
Local processing in your browser
Most FORMARTIO tools process your files entirely inside your own browser. Your PDFs, images, videos, and documents are not uploaded to our servers to be converted, compressed, or edited.
There is no backend that receives or stores the content you process. Computation happens in your device's volatile memory and, when you close the tab, that processing ends without leaving copies in the cloud.
For us, privacy is not an optional add-on: it is the technical architecture the platform is built on.
Web accessibility
- Design aligned with Web Content Accessibility Guidelines (WCAG) Level AA.
- Score of 96/100 on Google Lighthouse Accessibility on main pages.
- Verified color contrast, aria-label attributes on interactive controls, and correct semantic HTML structure for screen readers.
HTTP security headers
All site responses include security headers configured on the server. Verified with an A grade on securityheaders.com.
| Header | Value |
|---|---|
| Strict-Transport-Security (HSTS) | max-age=63072000; includeSubDomains; preload |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Permissions-Policy | camera=(), microphone=(), geolocation=() |
| Cross-Origin-Opener-Policy | same-origin |
GDPR and data privacy
- FORMARTIO complies with the General Data Protection Regulation (GDPR) in handling the limited information we do collect.
- No mandatory sign-up is required to use the free tools.
- We do not store processed files or conversion histories on our own servers.
- Third-party cookies (Google AdSense) are used for advertising purposes and can be managed from your browser settings.
Payments with Stripe
- Premium plan payment information is processed exclusively through Stripe.
- Stripe is PCI DSS Level 1 certified, the highest level of compliance in the payments industry.
- FORMARTIO never sees, processes, or stores card numbers or sensitive banking data.
- Stripe is the industry standard used by millions of businesses worldwide.
What we store and what we don't
Stored in your browser (localStorage)
- Light/dark theme preferences
- Tools marked as favorites
- Recently visited tools history
What we do NOT store
- PDF files, images, videos, or other documents you process
- Conversion content or generated results
- Personal data linked to your files
localStorage data stays on your device and is not transmitted to FORMARTIO servers.
Vulnerability reporting
If you discover a security issue in FORMARTIO, please report it responsibly. We investigate every report with priority and will respond as soon as possible.
contacto@formartio.com