FilePresto

Security and data protection pack

For the IT manager, data protection officer or information governance lead who must approve a new tool. Last updated 29th September 2026. Items that do not exist yet are marked planned. To keep a copy, use your browser's Print and choose Save as PDF.

Part A. Security answers

1. Are our files uploaded?

No. Files, file names and file contents are processed inside the web browser on your own device and are not sent to FilePresto or anyone else. A browser rule sent with every page (the content security policy) only allows the page to connect back to filepresto.com itself, and file contents are not included in any of those connections.

2. What does the site still connect to?

To filepresto.com only, to: load the page and the open-source software it uses; show prices in your currency (the visitor's country, as supplied by the host, is used for this and not stored); and, for paying users, check a purchase or team code. If someone chooses to buy, a new tab opens at Stripe's checkout. Nothing else.

3. What personal data does FilePresto receive?

From free users: the ordinary technical and security records needed to deliver and protect a website, which may include IP address, browser or user-agent information, requested URL, time of request and security-related request information. These records are held by Cloudflare under the settings and retention periods described in our privacy notice. From buyers: name, email address, the organisation's name, the payment reference, and a record of the terms the buyer accepted. From support: whatever you email us. Never the contents or names of your files.

4. Where is it processed?

Your files: on your own devices only. Our website and payment service: Cloudflare's global network. Payments: Stripe Managed Payments, whose merchant-of-record entity is the seller for the payment.

5. Which third parties are involved?

Cloudflare (hosting, the payment and price service, and sending our emails); Stripe and its merchant-of-record entity (payment, tax, receipts and invoices); GitHub (where our source code is kept; it never receives your data). No analytics, advertising or tracking companies.

6. What assurance do you have?

A published content security policy and other security headers on every page; open-source components pinned to stated versions with a public list of every file and its checksum. Automated accessibility tests run against every page on 28th September 2026 passed. Automated testing does not by itself establish full WCAG 2.2 AA compliance, and no independent accessibility audit has yet been carried out. Cyber Essentials: not yet held (planned). No independent penetration test has been carried out.

7. What happens if FilePresto stops trading?

The tools are ordinary web pages. A self-hosted edition, run on your own servers with no dependence on us, is planned; until it exists, organisation plans depend on filepresto.com being available.

8. Who is FilePresto?

FilePresto is a trading name of Brian Rooney, Office 1, Technology House, 9 Newton Place, Glasgow G3 7PR. Contact: [email protected]. Security reports: [email protected].

Part B. Data protection roles

B1. File contents and file names: FilePresto does not receive them, so it is neither controller nor processor for them. The processing happens on the organisation's own devices, as it would with an installed program. No data processing agreement is needed for the conversion function, and no international transfer of document contents takes place. This is the position the pack invites your data protection officer to confirm; FilePresto does not give legal advice.

B2. Website, licence and support information (purchaser details, team-code records, support emails, security records): FilePresto is controller, as set out in its privacy notice. FilePresto does not act as your processor.

B3. Payments: Stripe and its merchant-of-record entity process payment data under their own arrangements.

B4. Suppliers: Cloudflare processes technical and email data for FilePresto as FilePresto's supplier.

B5. If a future FilePresto feature ever processed personal data on an organisation's behalf, a full data processing agreement would be provided before that feature was offered.

B6. Privacy and data protection by design. FilePresto's architecture applies data minimisation by keeping document contents and file names on the user's device rather than collecting them centrally. This can help organisations meet their own privacy and data-protection-by-design requirements.

B7. Whether an organisation needs a data protection impact assessment depends on its own use of FilePresto and is for that organisation to decide.

Part C. Security architecture

C1. The pages. Static files (HTML, CSS, JavaScript and WebAssembly) served over HTTPS from Cloudflare. No server processes user files. No user database. No accounts.

C2. The privacy lock. Every page is sent with this content security policy: default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data:; media-src 'self' blob:; worker-src 'self' blob:; connect-src 'self' blob: data:; font-src 'self' data:; object-src 'none'; base-uri 'self'; form-action 'none'; frame-ancestors 'none'. The Office-to-PDF pages also send Cross-Origin-Opener-Policy same-origin and Cross-Origin-Embedder-Policy require-corp, and allow the Office engine to run code it builds as it starts. Every page also sends X-Content-Type-Options nosniff and Referrer-Policy no-referrer, and switches off camera, microphone and geolocation. These headers are as built on 29th September 2026 and are re-read from the live site after each release.

C3. What networking remains after a file is opened. The pages make three kinds of request to filepresto.com: fetching the page's own software, the price lookup, and purchase-code or team-code checks. File contents are not part of any request. The buy buttons open Stripe's checkout in a new tab by ordinary navigation; the file stays in the original tab and is not sent.

C4. The payment service. A small Cloudflare Worker at filepresto.com/api. It talks to Stripe and to a Cloudflare key-value store. Passes are digitally signed (ECDSA P-256) and held in the user's own browser; there is no user database. The store holds only: the signing key; refunded passes, identified by a shortened one-way fingerprint of the payment reference; a record of the terms each buyer accepted; flags that stop duplicate emails; short-lived rate-limit counters (some keyed to an IP address, deleted automatically within an hour); a price list cached for a day; and team-code records (C5). The application code does not deliberately write buyer or file information to its own application logs.

C5. Team codes. Each team code is generated with at least 128 bits of cryptographically secure randomness; is never placed in a web address or an application log; is not stored in recoverable form (only a one-way fingerprint is kept); is checked by a rate-limited service; can be replaced by the buyer; and stops when the plan ends, is cancelled or is refunded, because every check reads the live subscription.

C6. Records held by our host. Cloudflare keeps request and security records (including IP addresses) for delivering the site and protecting it. These are distinct from, and never contain, file names or contents.

C7. Administrative access. The accounts that control FilePresto (Cloudflare, Stripe, the email account that receives FilePresto mail, and GitHub) are protected by two-step sign-in.

C8. Supply chain. Every third-party component is listed with version, licence, source, served file and SHA-256 checksum. Upgraded libraries get new file names so old and new code cannot mix.

C9. Change control. Source is held in a private GitHub repository; changes are recorded in version control; production releases require owner approval through a pull request; previous production versions can be restored if a release causes a problem.

C10. Watching for vulnerabilities. Known vulnerabilities in the listed components are reviewed at least weekly and whenever a component changes. Target: a confirmed critical vulnerability in an internet-facing part of FilePresto is fixed or mitigated within five calendar days, sooner if it is being actively exploited. These are targets, not guaranteed resolution times.

C11. Incidents. Security reports go to [email protected] (also published in /.well-known/security.txt). FilePresto will acknowledge a report within two working days, assess it, contain it (if needed by restoring the previous version or suspending the payment service), and tell affected organisations without undue delay. FilePresto does not hold a stored repository of customer documents, so a breach cannot expose historical document contents stored by FilePresto because there are none. A compromise of the software served to users could nevertheless affect files subsequently opened in a compromised version, which is why code integrity, change control, rapid rollback and vulnerability response are treated as security controls.

C12. Testing. Done: automated accessibility tests of every page (28th September 2026); automated tests of the offer, checkout, pass handling and the whole team-code life cycle; a real Day Pass purchase and refund on the live site (28th September 2026). Not done: independent accessibility audit; independent penetration test; Cyber Essentials assessment.

C13. Residual risks. A compromised update to the public site could change what the pages do (mitigations: pinned components with checksums, recorded changes, the browser rule itself, rapid rollback, and, when available, self-hosting). The user's own device security matters, as for any installed program. Very large files are limited by the device's memory.

Part D. Supported browsers

Verified: a current Chromium-based desktop browser at phone and computer widths (automated tests of every page, 28th September 2026). Expected, not individually verified: current versions of Chrome, Edge, Firefox and Safari on Windows, macOS, iPadOS and iOS, and Chrome on Android. Office to PDF and large video need a desktop-class device.

Part E. Certification, insurance and continuity

Cyber Essentials: not yet held; planned. Insurance: not yet arranged. Self-hosted edition: planned; "no call home" is a design requirement for it and will be stated as a fact only once the package exists and has been tested.