Security

Enterprise-grade protection from day one.

No compromise on compliance, encryption, or audit logging.

🔐
Encryption

All data encrypted in transit and at rest using industry-standard algorithms.

  • TLS 1.2+ for all data in transit
  • AES-256 encryption for data at rest
  • API keys stored as hashed values — never readable
📋
Compliance certifications

Built on the same infrastructure as MakeForms — trusted by hospitals, healthcare entities, and NGOs worldwide.

  • SOC 2 Type II certified
  • HIPAA BAA available on Business plan
  • ISO 27001, GDPR, PIPEDA compliant
🌍
Data residency

Control where your documents live. Business plan accounts can choose their region.

  • US data centres (default)
  • EU data centres (GDPR-compliant)
  • Canadian data centres (PIPEDA-compliant)
⏱️
Uptime & reliability

Edge infrastructure built for production document generation.

  • 99.99% uptime SLA on Business plan
  • Automatic failover and redundancy
  • Status page at status.exporttopdf.com
🗑️
Document retention

Configurable retention settings let you control exactly how long documents are stored.

  • 7 days to indefinite retention, per template
  • Auto-delete on expiry — zero manual work
  • Password-protected PDFs on Business plan
📊
Audit logging

Full audit trail for compliance and debugging.

  • 30-day audit logs on Pro plan
  • 1-year audit logs on Business plan
  • Export audit logs for compliance reviews

Need a BAA or security questionnaire?

Business plan accounts can sign a BAA directly from account settings. For custom security reviews, reach out.