Security Practices
FileTools.io is built to minimize what could go wrong with your files, and to limit how long anything is kept around.
File handling
Every upload is validated on the server by its actual file content, not just its file extension, before any processing happens. Files are written to an isolated, per-job directory that only that job's workflow can access, and are never referenced by a user-controlled path.
Processing
File conversion and editing runs through fixed, non-interactive command invocations — user input is passed as data, never interpreted as part of a shell command. This is a deliberate design choice to rule out an entire class of injection vulnerabilities.
Automatic deletion
Uploaded and processed files are deleted from our servers within 1 hour, whether or not you download the result.
Network & access
The site is served over HTTPS. API endpoints are rate-limited to reduce abuse, and job results are only retrievable by their unique job ID — there is no directory listing or way to browse other users' files.
Dependencies
We track and update third-party dependencies to address known vulnerabilities as they're disclosed.
Reporting a security issue
If you believe you've found a security vulnerability, please email us at support@filetools.io with details. We ask that you give us a reasonable opportunity to address it before any public disclosure.