Managed Stirling PDF hosting

Collaboration and identityOn-prem or sovereign site

PDF merging, splitting, conversion, OCR, redaction and signing in the browser, run in Switzerland, the EU or your own datacentre instead of on a public PDF website. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about Stirling PDF

Licence
MIT and Stirling PDF User License
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
www.stirling.com

Running Stirling PDF in production: what it takes

  1. Deploy with a memory ceiling

    A version we have run, from the standard image with LibreOffice, Tesseract, OCRmyPDF, qpdf and Ghostscript inside. The container gets a memory ceiling, and session limits make a heavy OCR job queue instead of exhausting memory.

  2. Sign in through your IdP, analytics off

    OpenID Connect to Keycloak or your own IdP, password login off once an SSO administrator exists, analytics and URL to PDF off. It answers only on your private network.

  3. Treat every upload as hostile

    Each file comes from outside and is parsed by LibreOffice, Ghostscript and Tesseract. Upstream already runs LibreOffice with macros disabled and a syscall filter; we keep the image current, because a fix in one of those tools is a reason to upgrade on its own.

  4. Back up the configs and restore monthly

    Documents are not kept on the server. The configs directory is: settings, the user database and the signing certificate. It goes offsite daily, encrypted, and once a month we restore it into a scratch environment and sign in.

  5. Upgrade against your sample files

    Releases arrive every few weeks. The Pilae Agent tests each one on a copy with your sample files, waits for your approval and applies it in your window. An upgrade can change the schema of the user database, so the rollback is the backup taken just before, restored with the previous version.

What Stirling PDF is, and who runs it

Self-hosted Stirling PDF in place of public PDF websites

Stirling PDF is a web application for the PDF work every office does: merging and splitting, compressing an attachment, converting Word or Excel to PDF and back, running OCR on a scan, redacting, filling forms and signing. It has more than fifty tools, a REST API for nearly all of them, and a desktop app that can send the heavy jobs to your server rather than to a public cloud.

It is usually deployed to close a leak rather than to add a capability. Without an internal tool, people upload contracts, payslips and patient letters to whichever PDF website comes up first. Run on your own hardware, or on a dedicated machine in one of the six Swiss and EU Pilae Cloud regions (there are 12 in all), Stirling PDF keeps the file on a server you chose and a network that is yours.

Stirling PDF in production: OCR sizing, sign-on and patching

The server keeps almost no state. Documents stay in the user’s browser between operations, and the server holds only its settings, a small user database and the OCR language packs. What needs sizing is the processing. OCR and Office conversion are the expensive operations, so we size the machine for the heaviest job people run and cap how many of those jobs run at once. Sign-in goes through Keycloak or your own identity provider, and the service answers only on your private network.

Every file it opens came from somewhere else, and the image parses those files with LibreOffice, Ghostscript, qpdf and Tesseract. That makes patching the main job. Probes check the status endpoint every 60 seconds and alert an engineer. The configs directory, the only state worth keeping, goes offsite daily, encrypted, to your chosen country, and comes back in a monthly restore drill. Upgrades go through the Pilae Agent: tested on a copy with your sample files, approved by you, applied in your window and recorded in the console. For signature requests to people outside the organisation we run Documenso beside it.

Stirling PDF licence and editions

Everyone who signs in through your identity provider becomes a named account, so more than five people means a Team or Enterprise licence. Team also covers direct API calls, and offline licence activation is what an air-gapped site needs. We say which plan you need before deployment. Pricing for our operation is on request. Talk to us about the documents you want to keep in-house.

Stirling PDF is open core. Code outside a list of named directories is MIT. Login, single sign-on and audit logging are in proprietary modules, which the standard and fat images include. Those modules are under the Stirling PDF User License: source-available rather than open source, and usable without a subscription only for internal trial, evaluation or minimal use, within the limits the software enforces and outside client-facing or commercial contexts. The free plan covers up to five users and 1,000 document units a month for API calls, automation and AI; manual use of the tools is not counted. Team adds users in blocks of 100 and an external PostgreSQL database. SAML, the full audit log and offline licence activation are Enterprise. Any paid licence is held in your name, and the proposal says which plan your use needs.

Stirling PDF system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
4 vCPU · 8 GBUpstream sizes up to ten users at 2 cores and 4 GB, and up to fifty at 4 to 8 cores and 8 to 16 GB. OCR and Office conversion decide the size; merging and splitting cost little.
Scratch disk
50 GB SSDFiles over 50 MB are processed on disk rather than in memory, and conversions write temporary files. Upstream recommends 50 GB on SSD for ten to fifty users.
Database
H2 file · PostgreSQL on TeamHolds accounts, settings and API keys, not documents. The embedded H2 file lives in the configs volume. PostgreSQL is the only supported external database, needs a Team or Enterprise licence, and is what we use once the Enterprise audit log is on.
Sign-in
OIDC · SAML on EnterpriseOpenID Connect to Keycloak or Entra ID works on every plan. Each person who signs in becomes a named account, and named accounts count against the plan: five on the free one.
OCR languages
tessdata volumeThe standard image ships Tesseract packs for English, German, French, Portuguese and simplified Chinese. Other languages your documents are written in, such as Italian, go in a mounted tessdata directory before go-live.

Migrating from Adobe Acrobat online to Stirling PDF

Acrobat online, iLovePDF and Smallpdf hold almost nothing worth exporting. People uploaded jobs there, not a library. The exception is anything saved in the vendor's cloud storage, which is downloaded before the subscription ends. What has to move is a habit: someone needs to merge a scan or shrink an attachment, searches for a PDF tool and uploads the file to the first result. The work is making the internal tool quicker to reach than that. Merging, splitting, compression, conversion, OCR, redaction, form filling and signing carry over. Signature requests to people outside your organisation, with an audit trail, do not; that is a separate tool. The longer job is sizing OCR and Office conversion for your real files.

  1. Find out what people upload

    Proxy logs for the public PDF sites over the last ninety days show which teams use them. Asking those teams tells you what for: OCR on scans, Word to PDF, compression before email. That sets the sizing and the OCR languages.

  2. Size for the heaviest job

    A batch of scanned contracts through OCR, or a large spreadsheet through LibreOffice, decides the machine, not the headcount. We test with sample files from your own teams before go-live.

  3. Put it behind sign-on and bookmark it

    Accounts through Keycloak or Entra ID, the address pushed to managed browsers, and the tools nobody needs switched off so the menu stays short.

  4. Then block the public sites

    Once the internal tool is in use, your web filter blocks the public PDF sites with a page that points to it. Blocking before the replacement exists sends people to the next site on the list.

Stirling PDF configuration we set explicitly

# configs/settings.yml (excerpt) · acme-pdf · zur1
security:
  enableLogin: true
  loginMethod: oauth2          # after an SSO account was promoted to admin
  oauth2:
    enabled: true
    provider: keycloak
    issuer: https://sso.acme.internal/realms/acme
    clientId: stirling-pdf     # secret from SECURITY_OAUTH2_CLIENTSECRET
    scopes: openid, profile, email
    useAsUsername: preferred_username
    autoCreateUser: true
    blockRegistration: false

system:
  backendUrl: https://pdf.acme.internal   # SSO callbacks return here
  enableAnalytics: false       # PostHog and Scarf off, no consent banner
  enableUrlToPDF: false        # upstream: known security issues
  googlevisibility: false
  showUpdate: false            # upgrades arrive through the Pilae Agent
  fileUploadLimit: 500MB

storage:
  enabled: false               # alpha upstream; files stay in the browser

processExecutor:
  sessionLimit:
    libreOfficeSessionLimit: 2
    tesseractSessionLimit: 2
    ocrMyPdfSessionLimit: 2
  timeoutMinutes:
    libreOfficetimeoutMinutes: 10
    ocrMyPdfTimeoutMinutes: 20
An example configs/settings.yml for acme. Sign-in goes through Keycloak, analytics and URL to PDF stay off, and OCR and Office conversion are capped so a large batch queues instead of taking the machine. The file lives in your repository and is restored with the user database beside it.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running Stirling PDF

Pricing is on request: a fixed price for onboarding, then a monthly price for Stirling PDF, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

Stirling PDF: common questions

Is Stirling PDF open source?

Partly. The core is MIT-licensed open source. Login, single sign-on and audit logging are in proprietary modules that the standard image also contains, under the Stirling PDF User License, which is source-available rather than open source. The free plan covers up to five users; beyond that you need a Team or Enterprise licence from Stirling PDF, held in your name.

Do our documents leave our network?

No. Files are processed on one server, yours or a dedicated machine in the Pilae region you picked, in ISO 27001-certified datacentres. Between operations they stay in the browser, not on the server. Analytics are off in configuration, and the AI features stay off unless you ask for them.

Can Stirling PDF replace Adobe Acrobat?

Yes, for the everyday work people do in Acrobat or on public PDF sites: merge, split, compress, convert, OCR, redact, fill forms and sign. Shared signing works only between registered users and is still marked alpha upstream, and PDF/UA conversion is work in progress. For signature requests to people outside the organisation we run Documenso beside it.

How much hardware does OCR need?

More CPU than anything else Stirling PDF does. Upstream rates OCR the heaviest operation on CPU: Tesseract is single-threaded, and a scanned page is an image, which also costs memory. We size from your own files and set session limits, so a batch of scans queues rather than running the machine out of memory.

Can we see who processed which document?

Yes, on any plan, though without Enterprise only for 30 days. Every instance records who ran which operation on which file, and when. Without Enterprise the Documents page in Processor also lists only the most recent 40. The full audit log, with search, export and a retention you set, is Enterprise and is stored in the database. If you need to answer who redacted what last year, that decides the plan.

Also in collaboration and identity

Back to apps

Bring us your Stirling PDF. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.