Security

Last updated: September 28, 2026

Koutei PDF is a small service run by one person, so we keep the design simple: we hold as little data as we can, and we lean on established providers for the parts that are hardest to get right. This page describes what we do today.

1. Your documents

  • What you type into a template is sent over an encrypted (HTTPS) connection, rendered into your PDF or image, and sent back. We don't save it, and our logs don't record it.
  • Documents are rendered by worker processes kept apart from the web server, with a time limit and size limits on every render, so one heavy request can't hold up everyone else.

2. Accounts and access

  • Sign-in is handled by Supabase Auth. Passwords are stored only as salted hashes, and they never reach our own servers.
  • Every table in our database has row-level security, so a signed-in user can only read their own account records.
  • API keys are stored as one-way hashes; only the first few characters are kept for display.
  • Server credentials never reach the browser, and test systems use a separate database from the live service.

3. Payments

  • You enter your card details in Paddle's checkout, and they go straight to Paddle, our merchant of record. Full card details never pass through our servers. Paddle's payment notifications to us include only the card type, the last four digits, the expiry date and the name on the card.
  • Payment notifications from Paddle are checked against Paddle's signature before we act on them.

4. Infrastructure

  • The site runs on Vercel, the rendering engine on Railway and the database on Supabase. Our database provider encrypts stored data and takes daily backups, which are kept for 7 days.
  • We watch security advisories for the software we depend on and update it when fixes are released.

We don't yet hold formal security certifications such as SOC 2 or ISO 27001. The companies we build on publish their own; see our service providers.

5. Report a security problem

If you find a vulnerability, please email support@kouteisystems.com with Security in the subject line. Include what you found, how to reproduce it and the pages involved. We will confirm we received it and keep you updated while we fix it.

While you investigate, please:

  • use only your own accounts, and don't access, change or delete other people's data;
  • don't run denial-of-service, spam or social-engineering tests;
  • don't make a real payment or chargeback to test billing; and
  • give us reasonable time to fix the problem before you share details publicly.

If you act in good faith and follow these rules, we won't take legal action against you for your research. We don't currently offer paid bug bounties.

6. If something goes wrong

If a security incident puts your personal information at risk, we will tell you and the relevant regulators as the law requires. See our Privacy Policy for more.