Security Practices

FileTools.io is built to minimize what could go wrong with your files, and to limit how long anything is kept around.

File handling

Every upload is validated on the server by its actual file content, not just its file extension, before any processing happens. Files are written to an isolated, per-job directory that only that job's workflow can access, and are never referenced by a user-controlled path.

Processing

File conversion and editing runs through fixed, non-interactive command invocations — user input is passed as data, never interpreted as part of a shell command. This is a deliberate design choice to rule out an entire class of injection vulnerabilities.

Automatic deletion

Uploaded and processed files are deleted from our servers within 1 hour, whether or not you download the result.

Network & access

The site is served over HTTPS. API endpoints are rate-limited to reduce abuse, and job results are only retrievable by their unique job ID — there is no directory listing or way to browse other users' files.

Dependencies

We track and update third-party dependencies to address known vulnerabilities as they're disclosed.

Reporting a security issue

If you believe you've found a security vulnerability, please email us at support@filetools.io with details. We ask that you give us a reasonable opportunity to address it before any public disclosure.