Enterprise Security

Security First. Privacy Always.

Your documents are hosted in the EU. Choose managed storage with configurable retention, bring-your-own-bucket, or opt into stateless mode for in-memory-only processing. Full control. Complete peace of mind.

GDPR Compliant
EU Hosted
Stateless Option

Security Features

Built with privacy and security at every layer

EU

Germany Hosted

All data processing happens in the European Union. Our infrastructure is hosted in Frankfurt, ensuring GDPR compliance and data sovereignty.

  • EU-based infrastructure (Frankfurt)
  • GDPR compliant processing
  • No data transfers outside EU
  • German data protection standards
Secure

Flexible Storage

Choose how your documents are handled. Use managed storage with configurable retention, bring your own bucket, or opt into stateless mode for pure in-memory processing.

  • Managed storage with configurable retention
  • Stateless mode via storage: "memory" parameter
  • No content persisted in stateless mode
  • Full control over your data lifecycle
BYOB

Bring Your Own Bucket

Store generated PDFs directly in your own AWS S3 bucket. Maintain full control over your documents and access policies. More providers coming soon.

  • Direct upload to your AWS S3 bucket
  • Your encryption, your keys
  • Full access control
  • GCP, MinIO & more coming soon
Private

Your Data, Your Choice

Flexible storage options — managed storage by default, BYOB for full control, or stateless mode via request parameter for zero-retention processing.

  • Content logging off via request param
  • Stateless mode via storage: "memory"
  • Managed storage with retention policies
  • Only usage metrics retained

Technical Compliance

Complete transparency on our security practices

Data Processing
Processing Location Frankfurt, Germany (EU)
Data Storage Managed, BYOB, or stateless mode
Retention Period Configurable (stateless mode available)
Encryption TLS 1.3 in transit
Compliance Standards
GDPR Compliant
Data Residency EU only
Access Logs Usage metrics only
Audit Trail API calls logged (no content)

Bring Your Own Bucket

Need complete control over your generated documents? With BYOB, PDFs are uploaded directly to your AWS S3 bucket. Use your own encryption keys, access policies, and compliance controls. We never touch your files after generation.

AWS S3 Google Cloud Storage (soon) MinIO (soon) More providers coming
BYOB Configuration
{
  "storage": "byob",
  "bucket": "your-bucket-name",
  "region": "eu-central-1",
  "path": "generated-pdfs/"
}

Security FAQ

Common questions about our security practices

Where is my data processed?

All data processing occurs exclusively in our Frankfurt, Germany infrastructure. Your HTML content and generated PDFs never leave the European Union.

Is my document content stored?

By default, generated PDFs are stored with managed storage and configurable retention. You can opt into stateless mode by setting storage to "memory" in your API request — in that case, documents are processed in memory only and nothing is persisted. Alternatively, use Bring Your Own Bucket to store PDFs in your own AWS S3 bucket (more providers coming soon).

How does BYOB work?

With Bring Your Own Bucket, you provide your AWS S3 bucket credentials. Generated PDFs are uploaded directly to your storage, bypassing our infrastructure entirely for file storage. Support for GCP, MinIO, and other S3-compatible providers is coming soon.

What data do you retain?

We retain usage metrics: API call timestamps, credit consumption, and error codes. By default, request content and generated files are logged. You can disable content logging via a request parameter for fully memory-based processing. If you enable managed storage, generated PDFs are stored per your retention settings.

Is the service GDPR compliant?

Yes. Our EU-only infrastructure and flexible storage model ensure full GDPR compliance. Stateless mode is available via request parameter for zero-retention requirements. We can provide a DPA (Data Processing Agreement) upon request.

Can I get a DPA?

Yes. Enterprise customers can request a Data Processing Agreement. Contact us at support@pdf-mcp.io for more information.

Need More Information?

For enterprise compliance requirements, DPA requests, or security questionnaires, our team is here to help.

Ready for Secure PDF Generation?

Connect your AI Agent via MCP in 30 seconds. 100 free credits coupon on signup.