SAML Decoderv2.0Enterprise SAML 2.0 Toolkit
Zero Data Transmission Guarantee

Privacy Policy

Effective Date: September 17, 2026 • Last Reviewed: September 2026

Our Core Commitment: Zero Server Transmission

Every operation on SAMLDecoder.com — including SAML decoding, deflate inflation, XML formatting, X.509 certificate parsing, and claims inspection — runs 100% locally in your web browser. Not a single byte of your SAML payload, user identity, certificate, or cryptographic key is ever sent to our servers or any third-party.

1. Information We Do Not Collect

Unlike legacy developer utilities that rely on server-side processing (such as PHP backends), SAMLDecoder.com was architected specifically to eliminate data exposure risks for enterprise teams:

  • No SAML Payloads: We do not log, store, inspect, or transmit any raw SAML requests, SAML responses, XML assertions, or metadata you paste or upload.
  • No User Identity Data (PII): Employee email addresses, usernames, display names, telephone numbers, group memberships, and session indices remain strictly in your browser's runtime memory.
  • No Cryptographic Materials: Private certificates, public keys, and signatures are processed using the native W3C WebCrypto API and are instantly released from memory when you close or refresh the tab.

2. Local Storage and Browser State

SAMLDecoder.com uses the browser's standard localStorage API exclusively for user interface preferences:

  • theme: Stores your chosen visual mode (light or dark) to prevent flickering when reloading pages.

We do not store SAML tokens, history, or credentials in persistent browser storage. All inputs are cleared upon page refresh unless intentionally retained in your active browser session.

3. Cookies, Tracking & Analytics

We believe developer tools should be fast, quiet, and respect user privacy:

  • We do not set tracking cookies or advertising pixels.
  • We do not sell, rent, monetize, or share your usage data with data brokers or marketing platforms.
  • Standard web server hosting logs may record high-level, anonymized network metadata (such as IP address, browser user-agent, and requested asset path) strictly for network DDoS protection, CDN asset caching, and infrastructure stability. These server logs never contain SAML payload data.

4. Enterprise Compliance (GDPR, SOC 2, HIPAA)

Because SAMLDecoder.com does not collect, process, or store personal data on remote servers, using this tool does not create an external data processor relationship under European General Data Protection Regulation (GDPR) Article 28, nor does it violate HIPAA or SOC 2 confidential data boundaries.

Security analysts, penetration testers, and identity architects can safely debug real production tokens containing employee records without triggering enterprise data leak prevention (DLP) alerts.

5. Third-Party External Links

Our site may contain links to external specifications, standards bodies (such as the OASIS SAML 2.0 specifications), or browser extension marketplaces. We are not responsible for the privacy practices or content of external third-party domains.

6. Updates to This Privacy Policy

We may update this policy occasionally to reflect service improvements. Any modifications will be posted here with an updated revision date. Our core commitment to 100% client-side zero-transmission processing will remain absolute.

7. Contact Us

If you have any questions or security concerns regarding this privacy policy, please reach out to us at privacy@samldecoder.com or visit our Contact Page.