PDF merging, splitting, conversion, OCR, redaction and signing in the browser, run in Switzerland, the EU or your own datacentre instead of on a public PDF website. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.
- Licence
- MIT and Stirling PDF User License
- Runs on
- Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
- Upgrades
- Pinned, tested against your configuration, applied in your window
- Upstream
- www.stirling.com
Running Stirling PDF in production: what it takes
Deploy with a memory ceiling
A version we have run, from the standard image with LibreOffice, Tesseract, OCRmyPDF, qpdf and Ghostscript inside. The container gets a memory ceiling, and session limits make a heavy OCR job queue instead of exhausting memory.
Sign in through your IdP, analytics off
OpenID Connect to Keycloak or your own IdP, password login off once an SSO administrator exists, analytics and URL to PDF off. It answers only on your private network.
Treat every upload as hostile
Each file comes from outside and is parsed by LibreOffice, Ghostscript and Tesseract. Upstream already runs LibreOffice with macros disabled and a syscall filter; we keep the image current, because a fix in one of those tools is a reason to upgrade on its own.
Back up the configs and restore monthly
Documents are not kept on the server. The configs directory is: settings, the user database and the signing certificate. It goes offsite daily, encrypted, and once a month we restore it into a scratch environment and sign in.
Upgrade against your sample files
Releases arrive every few weeks. The Pilae Agent tests each one on a copy with your sample files, waits for your approval and applies it in your window. An upgrade can change the schema of the user database, so the rollback is the backup taken just before, restored with the previous version.
What Stirling PDF is, and who runs it
Self-hosted Stirling PDF in place of public PDF websites
Stirling PDF is a web application for the PDF work every office does: merging and splitting, compressing an attachment, converting Word or Excel to PDF and back, running OCR on a scan, redacting, filling forms and signing. It has more than fifty tools, a REST API for nearly all of them, and a desktop app that can send the heavy jobs to your server rather than to a public cloud.
It is usually deployed to close a leak rather than to add a capability. Without an internal tool, people upload contracts, payslips and patient letters to whichever PDF website comes up first. Run on your own hardware, or on a dedicated machine in one of the six Swiss and EU Pilae Cloud regions (there are 12 in all), Stirling PDF keeps the file on a server you chose and a network that is yours.
Stirling PDF in production: OCR sizing, sign-on and patching
The server keeps almost no state. Documents stay in the user’s browser between operations, and the server holds only its settings, a small user database and the OCR language packs. What needs sizing is the processing. OCR and Office conversion are the expensive operations, so we size the machine for the heaviest job people run and cap how many of those jobs run at once. Sign-in goes through Keycloak or your own identity provider, and the service answers only on your private network.
Every file it opens came from somewhere else, and the image parses those files with LibreOffice, Ghostscript, qpdf and Tesseract. That makes patching the main job. Probes check the status endpoint every 60 seconds and alert an engineer. The configs directory, the only state worth keeping, goes offsite daily, encrypted, to your chosen country, and comes back in a monthly restore drill. Upgrades go through the Pilae Agent: tested on a copy with your sample files, approved by you, applied in your window and recorded in the console. For signature requests to people outside the organisation we run Documenso beside it.
Stirling PDF licence and editions
Everyone who signs in through your identity provider becomes a named account, so more than five people means a Team or Enterprise licence. Team also covers direct API calls, and offline licence activation is what an air-gapped site needs. We say which plan you need before deployment. Pricing for our operation is on request. Talk to us about the documents you want to keep in-house.
Stirling PDF system requirements
Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.
- CPU and memory
- 4 vCPU · 8 GBUpstream sizes up to ten users at 2 cores and 4 GB, and up to fifty at 4 to 8 cores and 8 to 16 GB. OCR and Office conversion decide the size; merging and splitting cost little.
- Scratch disk
- 50 GB SSDFiles over 50 MB are processed on disk rather than in memory, and conversions write temporary files. Upstream recommends 50 GB on SSD for ten to fifty users.
- Database
- H2 file · PostgreSQL on TeamHolds accounts, settings and API keys, not documents. The embedded H2 file lives in the configs volume. PostgreSQL is the only supported external database, needs a Team or Enterprise licence, and is what we use once the Enterprise audit log is on.
- Sign-in
- OIDC · SAML on EnterpriseOpenID Connect to Keycloak or Entra ID works on every plan. Each person who signs in becomes a named account, and named accounts count against the plan: five on the free one.
- OCR languages
- tessdata volumeThe standard image ships Tesseract packs for English, German, French, Portuguese and simplified Chinese. Other languages your documents are written in, such as Italian, go in a mounted tessdata directory before go-live.
Migrating from Adobe Acrobat online to Stirling PDF
Acrobat online, iLovePDF and Smallpdf hold almost nothing worth exporting. People uploaded jobs there, not a library. The exception is anything saved in the vendor's cloud storage, which is downloaded before the subscription ends. What has to move is a habit: someone needs to merge a scan or shrink an attachment, searches for a PDF tool and uploads the file to the first result. The work is making the internal tool quicker to reach than that. Merging, splitting, compression, conversion, OCR, redaction, form filling and signing carry over. Signature requests to people outside your organisation, with an audit trail, do not; that is a separate tool. The longer job is sizing OCR and Office conversion for your real files.
Find out what people upload
Proxy logs for the public PDF sites over the last ninety days show which teams use them. Asking those teams tells you what for: OCR on scans, Word to PDF, compression before email. That sets the sizing and the OCR languages.
Size for the heaviest job
A batch of scanned contracts through OCR, or a large spreadsheet through LibreOffice, decides the machine, not the headcount. We test with sample files from your own teams before go-live.
Put it behind sign-on and bookmark it
Accounts through Keycloak or Entra ID, the address pushed to managed browsers, and the tools nobody needs switched off so the menu stays short.
Then block the public sites
Once the internal tool is in use, your web filter blocks the public PDF sites with a page that points to it. Blocking before the replacement exists sends people to the next site on the list.
Stirling PDF configuration we set explicitly
# configs/settings.yml (excerpt) · acme-pdf · zur1
security:
enableLogin: true
loginMethod: oauth2 # after an SSO account was promoted to admin
oauth2:
enabled: true
provider: keycloak
issuer: https://sso.acme.internal/realms/acme
clientId: stirling-pdf # secret from SECURITY_OAUTH2_CLIENTSECRET
scopes: openid, profile, email
useAsUsername: preferred_username
autoCreateUser: true
blockRegistration: false
system:
backendUrl: https://pdf.acme.internal # SSO callbacks return here
enableAnalytics: false # PostHog and Scarf off, no consent banner
enableUrlToPDF: false # upstream: known security issues
googlevisibility: false
showUpdate: false # upgrades arrive through the Pilae Agent
fileUploadLimit: 500MB
storage:
enabled: false # alpha upstream; files stay in the browser
processExecutor:
sessionLimit:
libreOfficeSessionLimit: 2
tesseractSessionLimit: 2
ocrMyPdfSessionLimit: 2
timeoutMinutes:
libreOfficetimeoutMinutes: 10
ocrMyPdfTimeoutMinutes: 20
What Pilae is responsible for
A pinned version
A version we have run, not whatever latest resolves to that day.
A runbook
What it depends on, how it fails, what to do about it. In your repository.
A restore drill
Backups restored on a schedule. A backup nobody has restored is a file.
A patch window
Security updates in a window you agreed, with a rollback ready.
Someone watching
Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.
- Where it runs
- zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
- Who holds the credentials
- You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
- If you leave
- The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.
What drives the price of running Stirling PDF
Pricing is on request: a fixed price for onboarding, then a monthly price for Stirling PDF, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.
- Instance size
- The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
- High availability
- One machine with tested restores, or a replicated setup that keeps serving when a node fails.
- Storage and backups
- How much data it holds, how long backups are kept, and point-in-time recovery for its database.
- Plan and support
- Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
- Region
- Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
- Sign-on and integrations
- Single sign-on, directory sync, mail relays and the other systems the app has to reach.
Stirling PDF: common questions
Is Stirling PDF open source?
Do our documents leave our network?
Can Stirling PDF replace Adobe Acrobat?
How much hardware does OCR need?
Can we see who processed which document?
Also in collaboration and identity
Keycloak
Single sign-on for everything else you run, with your own directory as the source of truth and no per-seat bill between you and it.
Replaces Okta, Microsoft Entra ID
Nextcloud
Files, calendars and shared documents for the whole organisation, on storage you can point at in a room you control.
Replaces Google Drive, Dropbox, SharePoint
Collabora Online
In-browser editing of Word, Excel and PowerPoint files beside Nextcloud, on your own hardware or in the Pilae region you choose, so no document passes through someone else's cloud.
Replaces Microsoft 365 for the web, Google Docs
Bring us your Stirling PDF. We will tell you what it takes.
Thirty minutes on the deployment you already have, or the one you are about to start.