Skip to content

Trust Center

Trust, verified.

A vendor you have not heard of should earn trust with evidence, not adjectives. Here is what you can verify today, what we share under NDA, and what is on the roadmap — labelled honestly.

Available now

Real and checkable today.

  • ISO/IEC 27001:2022 certified ISMS

    NextPDF is built by PATEON Network Technology, an information-security firm whose information-security management system is independently certified (cert. QCC/B86F/1224).

    Verify the certificate ↗ (opens in a new tab)
  • Apache-2.0 auditable core

    NextPDF Core and Connect are open source. Read the source, run the test suite, and audit exactly what runs in your process.

  • Verifiable conformance samples

    Every standards claim ships with the exact validator command and a real sample — run it through veraPDF, qpdf, or OpenSSL yourself, or generate one in the trial.

    Standards & how to verify them →
  • Privacy, DPA & sub-processors

    A GDPR-aligned Privacy Policy, a Data Processing Agreement scoped to hosted services, and a current sub-processor list.

    Legal & policies →
  • Coordinated vulnerability disclosure

    Report a security issue to [email protected]. We acknowledge, triage, and coordinate disclosure.

Under NDA

Shared with enterprise evaluators during procurement.

  • Penetration-test summary

    A summary of independent security testing and remediation status, available to enterprise evaluators under NDA.

  • Security architecture review

    The threat model, fail-closed design notes, and asset-handling controls in depth — for your security team during evaluation.

    Request under NDA →

Planned

On the roadmap — listed at its real status, not as a current capability.

  • SOC 2 Type II

    A SOC 2 examination is planned for the hosted Connect offering. Not yet attested — we will publish the report status here.

  • Published SBOM

    A signed software bill of materials per release is planned, to make the dependency surface auditable without cloning the repo.

Evaluate with the evidence in hand.

Start with the open-source core today, or talk to us about the under-NDA security artifacts for your review.