Security & Trust
How Adrian Headley Tools is operated, how browser tools handle data, which external services may be contacted, and how to report a security concern.
Operator and purpose
Adrian Headley Tools is a personal utility website operated by Adrian Headley. Its purpose is to provide practical browser-based tools for everyday tasks including text, files, PDFs, media, conversions, security checks and research utilities.
The site is part of the wider Adrian Headley portfolio at adrianheadley.com. The source is maintained in the public GitHub repository.
Privacy and data handling
The site is designed around a local-first approach. Many tools run entirely in the browser and do not send the text, document or file being processed to a Tools server.
Some features necessarily make direct browser requests to third-party public services, such as DNS and routing data, geocoding, temporary email, URL services or public search/archive services. Those services operate under their own policies. The site's Privacy Policy explains this distinction in more detail.
No first-party analytics or advertising tracker is intentionally loaded by the Tools site. The maintenance release dated 24 September 2026 also removes legacy Google Analytics and Google Fonts requests that remained on older pages.
Software supply chain
Where a browser tool needs a specialist runtime, dependencies are requested from established public CDNs using explicit version numbers. Examples include PDF.js, pdf-lib, Monaco, Pyodide, Tesseract.js, JSZip and Leaflet.
Version pinning reduces unexpected dependency changes. The site also removes unused legacy scripts and avoids loading third-party code on pages that do not need it.
The public source repository provides an additional way to inspect the static HTML, CSS and JavaScript delivered by the project.
Downloads and generated files
Downloads are generated only after a user chooses an export or save action. Depending on the tool, outputs can include common formats such as PDF, PNG, JPG, text, ZIP archives or the site's .ahcode project format.
The site does not intentionally install executable software, request a user to run an installer, or automatically download files without an explicit user action.
Report a security issue
If you believe you have found a vulnerability, unsafe behaviour, compromised page or incorrect security classification, please report it through the contact route on the Adrian Headley portfolio. Please include the affected URL, what you observed, and enough detail to reproduce the issue where it is safe to do so.
The machine-readable vulnerability disclosure file is available at /.well-known/security.txt.
Search, classification and reputation
Search engines, web filters and antivirus products maintain independent reputation and categorisation systems. Their classifications can differ, especially for newer or lower-traffic domains. This page exists to give both people and automated reviewers a clear description of the site's operator, purpose, data flows and security model.
The site publishes a sitemap, robots directives, structured data, a security.txt file and an IndexNow deployment workflow to make legitimate changes easier for supported search and indexing services to discover.