Security
TableHTML HK is designed for short-lived document conversion. This page describes controls included in the beta build and will be updated as the service changes.
Current controls
- HTTPS at the public service boundary.
- PDF signature, MIME, encryption, size, page-count and page-geometry validation.
- One conversion at a time per server, upload rate limiting and optional human verification.
- Immediate removal of source and rendered-page artifacts after conversion, with results expiring within one hour.
- Sandboxed result previews and script-free, remote-resource-free downloaded HTML.
- Explicit website origins and hostnames accepted by the conversion API.
Operational approach
Document text is excluded from application logs. Administrative access should use individual accounts, SSH keys and multi-factor authentication. Security updates, monitoring and deletion checks are part of the deployment runbook.
Report a concern
Please do not include a private document in an initial security report. Contact billycheung2210@gmail.com with a concise description and steps to reproduce.
安全措施摘要
公開服務使用 HTTPS,並檢查 PDF 格式、加密、大小、頁數及頁面尺寸。每台伺服器同一時間只處理一項轉換,並設上載速率限制及可選的人機驗證。
原始檔案及算繪頁面會在完成轉換後刪除,結果於一小時內到期。預覽在沙盒中顯示,下載的 HTML 不含指令碼或遠端資源。