Security & architecture
Every GhostX tool is built around one architectural decision: your files are processed by your own browser, not by our servers. This page explains exactly what that means, where the exceptions are, and how to verify all of it yourself — because a privacy claim you can't check is just marketing.
Verify it in 30 seconds
Open your browser's DevTools → Network tab, drop a file into any editor tool, and watch. You'll see static assets (the page, fonts, model files) and analytics pings — and no request carrying your file. You can also disconnect once a tool has loaded: a service worker caches the site's code, and models download once and are cached, so tools you've already used keep working offline. OCR and document scanning fetch their engines from a CDN on first use, so they need a connection until then.
The architecture
- 1
All file processing is client-side. PDF work runs on pdf-lib and pdf.js compiled to WebAssembly in your tab; images run in a Web Worker; audio/video runs on ffmpeg.wasm; speech transcription runs Whisper and name-detection runs a BERT model — both on your device via onnxruntime. Encryption and hashing use the browser's native WebCrypto (AES-GCM 256, PBKDF2, SHA-256).
- 2
Machine-learning models are served from our own domain, downloaded once and cached — no inference request ever carries your content to a third-party AI service. Third-party code the site does load: two processing engines fetched on first use at pinned versions — the OCR engine (Tesseract.js and its language data, from jsDelivr) and the document-scan edge detector (OpenCV.js, from docs.opencv.org) — which run locally on your file; Google Analytics (gtag.js) on every page; and Stripe's checkout script, only if you open the tip form.
- 3
Content Security Policy with no inline-script escape hatch. There is no
'unsafe-inline': each of our own inline scripts is pinned by a SHA-256 hash regenerated on every deploy, so an injected inline script won't run. External scripts are allowed by origin, not by hash — our own domain plus Google (Tag Manager, Analytics, gstatic), Stripe, docs.opencv.org, and cdn.jsdelivr.net. That last one serves any public npm package, so the policy limits where scripts come from; it doesn't pin exactly which files. - 4
Error reporting is scrubbed, and never includes your file. When a tool operation fails, analytics records the operation id and a short reason code (
needs-flatten,transcribe-oom) or the error's type name. Uncaught crashes send Google Analytics the error message after scrubbing — long tokens,blob:/data:URLs and quoted strings are replaced, and it's cut to 100 characters — so a short unquoted fragment of an error message can still get through. Crash alerts sent to the maintainer carry only the error's type name.
The exceptions — stated plainly
"Nothing leaves your browser" is the rule for file content. Four features deliberately do more, and each is scoped:
GhostSend & GhostBeam
One-time sends are end-to-end encrypted — the AES key lives only in the link's #fragment, which browsers never transmit. Our servers store and relay ciphertext they cannot decrypt. Beam is peer-to-peer: bytes stream browser-to-browser over WebRTC and never touch us at all.
Multi-signer documents
Co-signing needs coordination, so a Cloud Function handles invitations and status. The document itself is end-to-end encrypted with a key that lives only in the magic-link fragment — the function attests and coordinates, it never sees the PDF.
GhostSign document seal
When you finish signing, your browser sends a SHA-256 fingerprint of the finished PDF (plus the fingerprints already printed on its certificate) to our seal function, which signs it and gets an independent timestamp. We keep a permanent record of those fingerprints so we can later confirm a file is one we sealed. We never receive the document, its file name, or any signer's name or signature. If you choose to verify your email, Firebase Authentication sends you a one-time link; we keep only a fingerprint of the verified address.
GhostProof timestamps
Proving a file existed requires telling a timestamping authority something. Only the file's SHA-256 hash — blind, and additionally blinded with a random nonce — is submitted to OpenTimestamps calendars. The file itself never moves.
Redaction that actually redacts
Most "redact a PDF" tools draw a black rectangle over the text — and the text stays in the file underneath, recoverable by copy-paste. GhostRedact rasterizes every page, so the output has no text layer and the pixels under each box are replaced. You can check the result yourself: drop a redacted file on /verify and it re-extracts the text layer live — a rasterized redaction comes back with no selectable text. That check can't see pixels, so it won't catch a box you missed or misplaced: always look over the result. The optional certificate records the SHA-256 of both source and output. It's self-reported by the tool and not digitally signed, so it isn't proof of origin — it lets anyone confirm which files it describes and re-check the redacted file for remaining text.
Scope & honest limits
- • Metadata in PDFs and images (EXIF/XMP) is inspected and stripped client-side; the X-ray reports exactly what it found before you scrub.
- • Custom detection rules (your client names, ID patterns) are stored in this browser's local storage only — never uploaded. Redaction certificates and analytics count their matches as "custom", never by rule name or matched text.
- • Automatic PII detection is a review aid, not a compliance certification — structured data (numbers, emails, cards, IBANs) is caught deterministically, names via an on-device model that loads automatically on desktop-class devices (on phones, low-memory devices, and slow or data-saver connections it's offered as an opt-in download instead). Human review remains your obligation.
- • Passphrase-encrypted files (.gxenc) are only as strong as the passphrase and the device they're decrypted on. We can't recover a lost passphrase — by design, there is nothing to recover it from.
- • We review our code against these claims; a claim found wrong gets fixed or removed, not re-worded. There has been no independent third-party audit.