Back to Home
Official Vendor Compliance Document

Enterprise Data Privacy & Zero-Egress Attestation

Architectural & Regulatory Declaration for Client Confidentiality and Air-Gapped Operation.

Effective Date:August 2026
Classification:Public / Enterprise Compliance
Product:Papryx Desktop (Win64)

1. Executive Summary & Privacy Guarantee

Papryx Desktop is architected from the ground up as a 100% On-Device, Privacy-First PDF Workstation.

  • Zero Cloud Document Uploads: Under no circumstances are user documents, text content, image layers, form inputs, metadata, OCR scans, or file names transmitted to external servers, cloud databases, or third-party APIs.
  • 100% Localhost Binary Processing: All PDF manipulation, text editing, rasterization, OCR, format conversion, and encryption execute exclusively on the client computer's local CPU and RAM.
  • Strict Loopback Boundary (127.0.0.1): Internal application engines communicate strictly across local loopback sockets bound to 127.0.0.1 on ephemeral ports. No external network interfaces are ever opened for document processing.

2. Technical Architecture & Data Boundary

Capability SuiteExecution EnvironmentNetwork StateData Handled
PDF Direct Text & Font Editing100% LocalNone (Air-Gapped)PDF Binaries, 22 Bundled Fonts
Two-Way Office Conversions (.xlsx, .docx, .pptx)100% LocalNone (Air-Gapped)Local Document Streams
OCR Text Scanner & Image Enhancer100% LocalNone (Air-Gapped)Bundled Tesseract OCR Engine
Document Cryptography & Redaction100% LocalNone (Air-Gapped)AES-256 Passwords, Vector Scrubbing
Universal Image Studio & Resizing100% LocalNone (Air-Gapped)Local Image Buffers (PNG, JPG, WebP, TIFF, BMP)
Commercial Seat LicensingLocal + Cryptographic VerificationMinimal HTTPS HandshakeKey Hash, Hardware Hash. (0 document files, paths, or text).
Binary Auto-UpdatesFastly CDN Public Release CheckByte-Range HTTPS GETsPublic binary release hashes & compiled .blockmap delta chunks. (0 document data or telemetry).

3. Regulatory & Compliance Alignment

EU GDPR (Art. 25 & 28)

Zero cloud transmission eliminates cross-border data transfer risks, third-party sub-processors, and unauthorized cloud exposure.

India DPDPA 2023

Fully compliant with on-device sovereign data custody principles. No digital personal data payloads are ever collected or stored remotely.

US HIPAA Local Perimeter

Electronic protected health information (e-PHI) and patient records remain strictly within the covered entity's local workstation perimeter.

Client NDAs & Audit Confidentiality

Chartered Accountants, tax auditors, and legal professionals can process sensitive client balance sheets and contracts without breaching non-disclosure agreements.

4. Authorized Vendor Declaration

I hereby certify and declare that Papryx Desktop has been engineered and verified in accordance with the strict zero-egress and data privacy standards described herein.

Owais Ansari Signature
Owais Ansari
Founder & Principal Systems Architect
Ahmedabad, Gujarat, India • admin@papryx.app