Skip to content
FileMoat

Security

We built the moat so we can't see your files.

Privacy by promise isn't enough. FileMoat is designed so that your documents physically never reach us — and you can check that in thirty seconds.

No upload endpoint exists

Our server only hands out the website itself. There is no API that accepts files — not hidden, not optional. We couldn't receive your files even if we wanted to.

The browser enforces it

A strict Content-Security-Policy tells your browser the page may only talk to filemoat.com, and only to load its own code. Any attempt to send data elsewhere is blocked by the browser itself.

Self-hosted everything

Fonts, PDF engines and spreadsheet libraries are served from our own domain. No CDNs, no analytics, no ad networks, no third-party scripts that could watch what you do.

Memory only, then gone

Files are read into your tab's memory, processed, and handed back as a download. Close the tab and every trace disappears. We don't use cookies or local storage for your files.

Don't trust — verify

Check it yourself in 30 seconds

  1. 1

    Open the Network panel

    Press F12 (or ⌥⌘I on Mac), open the Network tab and tick “Preserve log”.

  2. 2

    Use any tool

    Drop a file and process it. You'll see the page's own code load — and no request carrying your file.

  3. 3

    Go offline

    Load a tool, switch off Wi-Fi, then use it. It keeps working — because everything happens on your device.

The small print

What we do see

Like every website, our hosting provider keeps short-lived technical logs of page requests (IP address, browser type, page visited) to keep the service secure and running. These logs never contain your files or their contents — the files simply never travel over the network.

Our Content-Security-Policy

default-src 'self';

connect-src 'self';

img-src 'self' data: blob:;

worker-src 'self' blob:;

object-src 'none';

form-action 'self';

frame-ancestors 'none';