Security Policy

Last updated: 3 October 2025

This Security Policy describes the measures pdf24-creator takes to protect the systems, data, and infrastructure that support our services. We are committed to maintaining a secure environment for all users and stakeholders who interact with our platform.


1. Scope

This policy applies to all systems, networks, applications, and data managed or operated by pdf24-creator, including web-based services, internal tools, and third-party integrations used in the delivery of our platform.


2. Information Security Principles

Our approach to security is guided by three core principles:

Confidentiality - Access to data is restricted to authorised individuals and systems only. Sensitive information is protected against unauthorised disclosure at all stages of processing and storage.

Integrity - Data is protected against unauthorised modification. We implement controls to ensure that information remains accurate and complete throughout its lifecycle.

Availability - Systems and services are maintained to ensure reliable access for authorised users. We implement redundancy and recovery procedures to minimise disruption.


3. Access Control

3.1 User Authentication

Access to platform services requires verified credentials. We support and encourage the use of strong, unique passwords and multi-factor authentication where available. User sessions are protected using secure token mechanisms with defined expiry periods.

3.2 Privileged Access

Administrative and elevated access rights are granted on a least-privilege basis. Such access is reviewed regularly and revoked promptly when no longer required. All privileged actions are logged for audit purposes.

3.3 Third-Party Access

Access granted to third-party service providers is limited to what is strictly necessary for the performance of their services. Providers are required to maintain security standards consistent with this policy.


4. Data Protection

4.1 Encryption in Transit

All data transmitted between users and our platform is encrypted using industry-standard protocols. We enforce secure connections across all public-facing endpoints and prohibit the use of deprecated or insecure protocol versions.

4.2 Encryption at Rest

Sensitive data stored within our systems is encrypted using current encryption standards. Encryption keys are managed through dedicated key management procedures with appropriate access restrictions.

4.3 Data Minimisation

We collect and retain only the data necessary for the operation and improvement of our services. Data that is no longer required is securely deleted in accordance with our data retention schedule.


5. Network Security

Our network infrastructure is protected through a combination of firewalls, intrusion detection systems, and traffic monitoring. Network segments are separated based on sensitivity and function. Unnecessary ports, protocols, and services are disabled by default.

External-facing systems are regularly assessed for vulnerabilities, and network access is controlled through defined rules that are reviewed on a periodic basis.


6. Application Security

6.1 Secure Development

Security is integrated into our software development lifecycle. Developers follow secure coding guidelines and code is subject to review processes that include security considerations. Known vulnerability classes are addressed during development rather than post-deployment.

6.2 Vulnerability Management

We conduct regular vulnerability assessments of our applications and infrastructure. Identified vulnerabilities are prioritised and remediated according to their severity. Critical issues are addressed on an expedited basis.

6.3 Dependency Management

Third-party libraries and software components are tracked and updated to address known security issues. Outdated or unsupported dependencies are replaced in a timely manner.


7. Incident Response

7.1 Detection and Reporting

We maintain monitoring systems to detect unusual activity, potential breaches, and system anomalies. Security events are logged and reviewed. Users and employees are encouraged to report suspected security incidents promptly.

7.2 Response Procedures

Upon detection of a security incident, a defined response process is initiated. This includes containment of the issue, assessment of impact, remediation, and where appropriate, notification of affected parties. Incidents are documented and reviewed to improve future response.

7.3 Communication

Where a security incident affects user data or service availability, affected users will be notified in a timely manner with relevant information about the nature of the incident and the steps being taken.


8. Physical Security

Systems and infrastructure used to deliver our services are hosted in facilities that maintain appropriate physical access controls, environmental protections, and monitoring. Physical access to sensitive systems is restricted to authorised personnel only.


9. Employee and Personnel Security

All personnel with access to systems or data are subject to security awareness training. This includes understanding of acceptable use, handling of sensitive information, and recognition of social engineering and phishing attempts.

Access rights for personnel are reviewed when roles change and are revoked upon departure. Confidentiality obligations are maintained throughout and beyond the period of engagement.


10. Business Continuity and Recovery

We maintain backup procedures for critical data and systems. Backups are stored securely and tested periodically to verify their integrity and recoverability. Recovery procedures are documented and reviewed to ensure they remain effective in the event of a disruption.


11. Responsible Disclosure

We welcome reports from security researchers and members of the public who identify potential vulnerabilities in our systems. If you believe you have discovered a security issue, please contact us at support@oaklinefurnitures.com with a clear description of the issue. We ask that you refrain from publicly disclosing the issue until we have had a reasonable opportunity to investigate and respond.

We commit to acknowledging receipt of reports promptly and to working in good faith to address confirmed vulnerabilities.


12. Third-Party and Supply Chain Security

We assess the security posture of third-party vendors and service providers before engagement and on an ongoing basis. Contracts with third parties include appropriate security requirements. We monitor for changes in the risk profile of our supply chain and take action where necessary.


13. Audit and Compliance

Our security controls are reviewed on a regular basis to assess their effectiveness and alignment with current threats and best practices. Internal reviews are supplemented by periodic independent assessments where appropriate. Findings are used to drive continuous improvement of our security programme.


14. Policy Review

This Security Policy is reviewed at least annually and updated as required to reflect changes in our systems, services, threat landscape, or operational practices. The most current version of this policy is always available on our website.


15. Contact

For questions or concerns relating to this Security Policy, or to report a security issue, please contact us using the details below:

pdf24-creator

46 Edward Tyler Rd, Exhall, Coventry CV7, United Kingdom

Email: support@oaklinefurnitures.com

Phone: +44 7966 485425