{
  "id": 12935089,
  "title": "Why are we still uploading confidential PDFs to cloud servers just to merge pages?",
  "url": "https://urgent.news/2026/10/08/why-are-we-still-uploading-confidential-pdfs-to-cloud-servers-just-to",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T19:18:32.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/aqsam_husnain/why-are-we-still-uploading-confidential-pdfs-to-cloud-servers-just-to-merge-pages-27jk"
  },
  "original_language": "en",
  "account": "In 2026, developers building web tools often follow the standard microservice architecture. When users upload sensitive documents—bank records, tax PDFs, contracts—over the wire, a backend server spins up CPU threads to merge the pages. This process stores temporary files, consumes egress bandwidth, and risks exposing personally identifiable information if the server is compromised.\n\nRecently, the author of UtilifyAI's PDF suite transitioned away from this traditional approach to a 100% client-side solution. By utilizing pdf-lib, browser WebAssembly, and Blob APIs, all the heavy lifting—such as merging PDF pages—now occurs directly on the client's computer. The result is zero compute and storage overhead, as the client handles ArrayBuffers directly. Additionally, this zero-server approach ensures instant GDPR and HIPAA compliance, as files never leave the user's device. Offline resilience is also improved, as the tool works seamlessly with spotty internet connections once the files are cached.\n\nThe author has detailed the complete code breakdown of this client-side PDF merging process on Dev.to in an article: \"How to Merge PDF Files in the Browser Without Server Uploads.\" The piece raises an important question for developers: where should the line be drawn between client-side processing (considering memory pressure on low-end devices) and server-side offloading? Have you transitioned other traditionally backend operations—like image compression, EXIF scrubbing, or OCR—entirely to the browser as well?",
  "summary": "When building web tools in 2026, many of us default to standard microservice architecture: The user uploads sensitive documents (bank records, tax PDFs, contracts) over the wire. A backend server (Python/PyPDF2, Poppler, or headless Chrome) spins up CPU threads to stitch pages. The server stores temp files, burns egress bandwidth, and exposes document PII to server compromise. I recently…",
  "key_points": [
    "Developers traditionally merge PDFs on backend servers, risking data exposure.",
    "UtilifyAI's PDF suite now merges PDFs client-side using pdf-lib and WebAssembly.",
    "Client-side merging eliminates server overhead, ensures compliance, and improves offline resilience."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}