On by default. Every saved PDF is rebuilt clean — scripts, auto-run/event actions, launch actions and embedded payloads are removed. Auto-code removal is always applied by the rebuild and can’t be disabled; the toggles control links, unpacking, remote references and form widgets.
Shows on page previews, the big-page reader, and PNG exports. The saved PDF itself is not modified.
For watermarks flattened into the page (not a layer). Finds text objects that contain only this phrase — any font, any rotation — and cuts them from every page, in the preview and the saved PDF. Other text is kept.
The PDF attack catalog & taxonomy crosswalk — 37 techniques mapped to MITRE ATT&CK / ATLAS, CWE, OWASP and CAPEC, each with the control that detects or removes it. Opens in a panel over the editor; press Esc to close.
—Markdown, RAG JSON and Docling downloads get a SHA-256 hash, a per-chunk Merkle root (JSON), and an RSASSA-PKCS1-v1_5 signature. An RSA-4096 key is generated in your browser; the private key is non-extractable and stored in IndexedDB — it persists across sessions, but its bytes can never be read out or exported, even by this tool. Clear it any time. Each export embeds its own public key, so it self-verifies.
Load a Markdown or RAG JSON file this tool signed to confirm it hasn't been altered and see the signer's fingerprint. No key needed — it checks against the public key embedded in the file.
On by default. Removes the listed characters from reconstructed Text, Markdown and the full RAG JSON — including PDF metadata, form-field values and layer names. The recommended preset drops control, zero-width and bidirectional-override characters — the invisible payloads used to hide instructions from a reader or reorder text an LLM ingests. Applies on save and to new parses.