Open-source project
freedomofpress/dangerzone avatar
freedomofpress/dangerzone

Dangerzone: Converting Untrusted Documents into Safe PDFs

Take potentially dangerous PDFs, office documents, or images and convert them to safe PDFs

5,776 stars273 forksPythonAGPL-3.0

At a glance

What is it?
Dangerzone is a desktop application from Freedom of the Press Foundation that converts untrusted PDFs, office documents, and images into safe PDFs inside a sandbox with no network access. This article covers how it works, how to install it, and where its limits lie.
Who is it for?
Dangerzone is for journalists, researchers, and anyone who regularly receives documents from untrusted sources and wants a sandboxed conversion step before opening them. It is not for people who need to edit documents, preserve exact formatting, or work with scanned files that have no text layer unless they enable OCR.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Dangerzone Solves and Who It Is For

Dangerzone addresses a specific problem: you receive a document from a source you do not fully trust, and opening it in a normal PDF viewer or office suite means running whatever code or exploit it contains. The README describes the use case directly: you give it a document you do not know if you can trust, such as an email attachment. The project is built for that scenario, not for general document management.

The intended audience is visible in the project's origin. Dangerzone was inspired by Qubes trusted PDF, a technique described in a 2013 blog post by Joanna Rutkowska, and it is maintained by Freedom of the Press Foundation, an organization that supports journalists. The README links to a Guardian article about working with Qubes OS and to a GIJN Toolbox roundup of investigative tools. Those references point to a user base of journalists, researchers, and security-conscious individuals who handle documents from unknown senders.

It is not a document editor, a viewer, or a file manager. It takes a file, produces a new PDF, and optionally opens it in your chosen viewer. That narrow scope is deliberate.

How the Sandbox Conversion Works

The README describes the mechanism in plain terms. Inside a sandbox, Dangerzone converts the document to a PDF if it is not already one, then converts that PDF into raw pixel data: a huge list of RGB color values for each page. Then, outside the sandbox, Dangerzone takes this pixel data and converts it back into a PDF. The output contains only rendered page images, not the original document structure, scripts, or embedded objects.

The sandbox itself is a Podman container rather than a virtual machine. The README states that Dangerzone uses Podman containers as sandboxes instead of virtual machines, and that the containers use gVisor, an application kernel written in Go that implements a substantial portion of the Linux system call interface. Sandboxes have no network access, so a compromised container cannot exfiltrate data. That combination of container isolation plus gVisor plus network isolation is the core security argument.

After conversion, Dangerzone can optionally OCR the safe PDF to restore a text layer, and it compresses the output to reduce file size. The README also notes that Dangerzone can open the safe PDF in your chosen viewer, which allows you to set it as the default handler for PDFs and office documents so you do not accidentally open a dangerous file directly.

Installing Dangerzone and Converting Your First Document

Installation instructions live in INSTALL.md, linked from the README for each platform: macOS, Windows, Ubuntu Linux, Debian Linux, Fedora Linux, Qubes OS (beta), and Tails. The README does not reproduce the commands inline, so the exact package manager invocations and download steps are in that file rather than here.

For development or building from source, the repository uses Poetry. The Makefile defines a poetry-install target that runs:

bash
make poetry-install

That target runs `poetry install`, which installs the dependencies listed in pyproject.toml, including PySide6, PyMuPDF, and click. The project requires Python >=3.10,<3.15 according to pyproject.toml.

The CLI entry point is defined in pyproject.toml as:

bash
dangerzone-cli = "dangerzone.cli:run"

So after installation, the `dangerzone-cli` command is available. The README does not give a full CLI usage example, so consult the project documentation for the exact flags. The GUI entry point is:

bash
dangerzone = "dangerzone.gui.run:run"

Running `dangerzone` launches the graphical application. The README's screenshots show a settings panel and a conversion view. After conversion, the app lets you open the safe PDF in your PDF viewer of choice.

Limitations and Cases Where Dangerzone Is the Wrong Tool

Dangerzone converts documents to images wrapped in a PDF. That means the output has no selectable text unless you enable OCR. The README says Dangerzone can optionally OCR the safe PDFs it creates, so it will have a text layer again. If you need to copy text, search within the document, or feed the output into a text extraction pipeline, you must turn OCR on, and OCR is not perfect.

The conversion also discards document structure. Forms, links, bookmarks, and embedded files do not survive the pixel-data round trip. If your workflow depends on any of those, Dangerzone produces a less useful file.

Platform support is uneven. Hancom HWP files (.hwp, .hwpx) are listed as not supported on Qubes OS, with a link to issue 494. Qubes OS itself is labeled beta in the README. If you are on Qubes, you are on a less-tested path than macOS, Windows, or the major Linux distributions.

Finally, Dangerzone is a desktop application. The README does not describe a server mode, a REST API, or a headless batch conversion service. If you need to process documents automatically on a server, this is not the tool for that job.

How Dangerzone Differs from Qubes Trusted PDF

The README states that Dangerzone was inspired by Qubes trusted PDF but works in non-Qubes operating systems, using Podman containers as sandboxes instead of virtual machines. That is the central architectural difference.

Qubes trusted PDF relies on Qubes OS's disposable VMs. A VM boundary is stronger than a container boundary because it includes a separate kernel. Dangerzone substitutes a container running under gVisor, which the README describes as an application kernel written in Go that implements a substantial portion of the Linux system call interface. gVisor interposes on system calls, which narrows the attack surface compared to a plain container, but it is still not a hypervisor.

The trade-off is portability for isolation strength. Dangerzone runs on macOS, Windows, and several Linux distributions without requiring Qubes OS. If your threat model demands VM-level isolation and you already run Qubes, the original trusted PDF approach remains the stronger option. If you need something that works on a standard laptop, Dangerzone is the practical choice.

Maintenance, Updates, and Licence

The repository is not archived, and the last push was on 2026-09-17. The most recent release listed is v0.11.0 from 2026-07-02, following v0.10.0 in December 2025. That cadence suggests the project receives periodic releases rather than continuous updates.

The README's FAQ addresses updates directly. To check your version, run Dangerzone and look for a series of numbers to the right of the logo within the app, formatted like `0.4.1`. Then compare against the download page at dangerzone.rocks. If the download page shows a higher version, update. The FAQ frames updating as the simplest path to resolving issues, since updates fix problems as well as add features.

For airgapped environments, the README says Dangerzone is designed to run without any configuration. Updating the container image in an airgapped setup requires following the instructions in docs/developer/independent-container-updates.md.

Dangerzone is licensed under AGPL-3.0. The copyright lines in the README cover 2022 to 2024 for Freedom of the Press Foundation and contributors, and 2020 to 2021 for First Look Media. AGPL-3.0 is a copyleft licence with a network-use clause. If you modify Dangerzone and offer it as a network service, the licence likely requires you to publish your modifications. That is a summary of the licence text, not legal advice; consult a lawyer for your specific situation.

Editorial conclusion

Dangerzone is for journalists, researchers, and anyone who regularly receives documents from untrusted sources and wants a sandboxed conversion step before opening them. It is not for people who need to edit documents, preserve exact formatting, or work with scanned files that have no text layer unless they enable OCR. Before relying on it, verify that your platform is supported in INSTALL.md, check the version number in the app against the download page, and confirm whether your threat model requires the stronger isolation of Qubes OS rather than Podman containers.

Frequently asked questions

How do I install Dangerzone?

The README points to INSTALL.md, which has separate instructions for macOS, Windows, Ubuntu, Debian, Fedora, Qubes OS, and Tails. Follow the section for your platform.

Can Dangerzone run without an internet connection?

Yes. The README states that Dangerzone is designed to run in airgapped environments without any configuration. To update its container image in an airgapped setup, follow the instructions in docs/developer/independent-container-updates.md.

Does Dangerzone preserve the text in my documents?

Only if you enable OCR. The README says Dangerzone can optionally OCR the safe PDFs it creates, so it will have a text layer again. Without OCR, the output PDF contains page images rather than selectable text.

Has Dangerzone been security audited?

Yes. The README states that Dangerzone received its first security audit by Include Security in December 2023, and the audit was generally favorable, identifying no high-risk findings, only 3 low-risk and 7 informational findings.

Can I use a different Podman version with Dangerzone?

On Windows and macOS, Dangerzone embeds Podman, so there is no need to. To use a different Podman version such as Podman Desktop, the README points to the project's documentation at docs/podman-desktop.md.

Official sources

  1. freedomofpress/dangerzone on GitHub
  2. License: AGPL-3.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/freedomofpress-dangerzone.svg)](https://hysenlabs.com/projects/freedomofpress-dangerzone)