RC-SECURITY

Security

Version 2.0 Effective 10 October 2026

Scope

RenderCheck and the free image-to-text tool are in beta. This page lists what is in place today. It does not claim any certification, such as SOC 2 or ISO 27001.

How images are handled

Text recognition runs in your browser, using Tesseract.js and WebAssembly. The recognition engine and the English language data are served from this site's own address, under /ocr/, and not from a third party.

An automated test in the project repository runs recognition on a sample image. It fails if the browser makes any request to another address, or any request other than a plain page or file download, while recognition runs.

Architecture

Two surfaces share one rule: an image is read on the machine that holds it. The full write-up, with a table linking each claim to its test, is in docs/ARCHITECTURE.md.

RenderCheck architectureIn the browser, the page sends the image to a Web Worker that runs Tesseract in WebAssembly. A network proof counts requests. In a test runner, the matcher calls verifyText, which runs Tesseract in Node and writes a failure report. The host serves static files only, and the Content Security Policy blocks requests to any other server.YOUR BROWSERReact apppages and toolsOCR Web Workersame-origin moduleTesseract (WASM)self-hosted at /ocrNetwork proofrequests and bytes outimagePixels never leave this box. connect-src 'self' blocks every other destination.TEST RUNNER (PLAYWRIGHT OR CYPRESS)toShowTextmatcherverifyTextcoreTesseract (Node)English model bundledFailure reportJSON and outlined PNGStatic host (Vercel): files onlyHTML, JS, WASM and the English model. No upload endpoint.served
The Content Security Policy (connect-src 'self') is what blocks requests to other servers. Source: docs/ARCHITECTURE.md.
  • React app: src/core/ocr/engineClient.ts
  • OCR Web Worker: src/core/ocr/engine.worker.ts
  • Network proof: src/core/privacy/networkProof.ts
  • toShowText matcher: packages/rendercheck/src/playwright/matcher.ts
  • verifyText: packages/rendercheck/src/core/verify.ts
  • Failure report: packages/rendercheck/src/core/failures.ts

Verify it yourself

  1. Open the image-to-text tool and open your browser's developer tools on the Network tab.
  2. Choose an image. The tool shows a live count of requests and bytes sent while it reads the image.
  3. In the Network tab, check that no request carries your image. Only the page's own files load.

The count in the tool only covers the page itself. The Content Security Policy below is what stops the recognition worker from reaching any other address.

Security headers

The site sets these response headers (see vercel.json in the repository):

  • A Content Security Policy that limits scripts, workers, images and network connections to this site.
  • Strict-Transport-Security, so browsers use HTTPS.
  • X-Frame-Options: DENY, so other sites cannot embed these pages.
  • X-Content-Type-Options: nosniff.
  • A Permissions-Policy that turns off camera, microphone and location access.

Third-party requests

There are none. Fonts, scripts and the OCR engine are served from this site, and the Content-Security-Policy blocks requests to any other origin.

Reporting a vulnerability

Please email rajasekaran.parthiban7@gmail.com with the steps to reproduce the problem. Please do not open a public issue for a security problem.