Untrusted by default
Files are decoded only by the active local converters. Unsupported types are not sent elsewhere or relabeled as another format.
Local processing, output signature checks, safe headers, and temporary downloads protect every active conversion route.
Last updated: August 20, 2026
Files are decoded only by the active local converters. Unsupported types are not sent elsewhere or relabeled as another format.
Active conversion runs in the browser and output files use temporary object URLs that are revoked when jobs are removed or the page closes.
Output signatures and decodability are checked before the interface exposes a download.
Report suspected vulnerabilities to convert@novusstreamsolutions.com with “security” in the subject line. Do not attach sensitive source files or live exploit payloads to an initial report; describe the issue and we will follow up with a safe reproduction path.