PDFMergely for your organization
The PDF toolkit your security team does not have to worry about, because your documents never reach us, or anyone else.
Why it is easy to approve
No document egress
Documents are processed in the browser and never transmitted. There is no upload endpoint, no server-side processing, and no third party in the document path. What your team opens never leaves their machines.
Enforced, not promised
A Content-Security-Policy allow-list makes the browser itself refuse connections to anything beyond the app and a short list of analytics hosts, which your web filter can block outright. The claim is verifiable in one minute from any workstation.
Nothing to install or manage
No desktop software, no browser extension, no admin rights, no accounts. The attack surface your team adds is a website that cannot receive their files.
Works offline and on managed networks
After the first visit the app is cached and keeps working without a connection, including on restricted networks where upload-based tools simply fail. The heavyweight OCR, scan and repair engines download on first use, so run those once online if you want them offline.
Your reviewers should not take any of this on faith: the proof page shows how to verify the no-upload claim from any machine with the browser's own network panel, or by simply going offline.
Rolling it out is one allowlist entry
- Allowlist pdfmergely.com in your web filter. That is the whole deployment: no installer, no license keys, no per-seat anything.
- Recommend it internally the way it was first used: as the sanctioned answer to "how do I merge these PDFs?" before someone uploads a contract to a random website. An intranet link next to your other approved tools is usually all it takes.
- No new data-protection surface for documents. Since documents are never transmitted or stored by us, using the tools does not add a processor relationship or retention questions for your documents.
PDFMergely started as an internal tool, built so colleagues would stop uploading sensitive documents to random converters. The public site is that same idea, kept free. If your organization wants to talk, partnerships, security review, or an internal rollout, we answer personally.
Frequently asked questions
What data leaves the browser?+
Documents: none. Files are processed entirely on the device and there is no upload endpoint to receive them. The remaining traffic is fetching the app itself plus cookieless page analytics (Google Analytics sets cookies only on opt-in; a Cloudflare beacon reports page metrics). Neither ever contains file names or contents, and both analytics hosts can be blocked at your web filter with zero loss of functionality.
Do our employees need accounts?+
No. There are no accounts, no sign-up and nothing to provision. Anyone with a browser can use every tool immediately, which also means there are no credentials for your team to manage or for anyone to phish.
Is it really free for commercial use?+
Yes. Every tool is free, including for business use, with no seat limits, trials or paid tier. Because processing happens on your devices rather than our servers, there are no per-file server costs behind the tools.
Can we get a build for internal hosting, or a partnership?+
There is no self-hosted build today. For anything else, from walking your security team through the architecture to partnership questions, write to partnership@pdfmergely.com and a person will answer.