LicenseResizer
PrivacySecuritySubprocessorsTermsSupport
Trust center

Security at LicenseResizer

Our primary security control is data minimization: driver's-license images and generated PDFs are processed locally and are not uploaded to LicenseResizer.

Effective July 19, 2026

Data boundary

The browser decodes, analyzes, corrects, and composes the document on the user’s device. Source images and generated PDFs remain in volatile browser memory unless the user downloads or shares them. No LicenseResizer image or PDF ingestion endpoint exists.

Application safeguards

  • HTTPS with strict transport security and restrictive browser security headers.
  • Organization authentication and role enforcement through Clerk.
  • Server-side organization and administrator authorization on dealer APIs.
  • Signed Stripe webhook verification.
  • Allowlisted, size-limited workflow events that exclude document content.
  • Same-origin image-processing and PDF dependencies.
  • Source metadata removal through browser decoding and canvas re-encoding.
  • Encoded-file and decoded-pixel limits for untrusted images.
  • Camera-track shutdown and object-URL cleanup when sessions are cleared or replaced.
  • A service-worker policy that excludes images, media, Blob URLs, and PDFs from application caching.

What activity reporting means

Authorized dealer administrators can see preparation and handoff-option events. A “share sheet opened,” “email draft opened,” “text draft opened,” or “downloaded” event is not proof that the customer sent a file or that the dealership received it.

Residual risks

Risk remains in the customer’s browser and operating system, downloaded files, selected share applications and recipients, dealership systems, compromised devices, third-party providers, public dealer-link discovery, and inaccurate or poor-quality source images. Printer scaling can also change physical output.

Dealership security responsibilities

Dealerships remain responsible for their information-security program, access controls, workforce practices, vendor oversight, secure receipt channels, retention, deletion, incident response, and regulatory obligations. LicenseResizer documentation supports review but does not itself certify a dealership’s compliance.

Report a vulnerability

Email security@licenseresizer.com with a clear description, reproduction steps, affected URL, and potential impact. Do not include real license images, customer information, credentials, or destructive test results. We ask researchers to avoid privacy violations, service disruption, and accessing data that is not their own.

LicenseResizer prepares documents locally. It does not verify identity, authenticate licenses, choose recipients, or confirm delivery.

Return home